SPF, DKIM, and DMARC are domain-based email authentication mechanisms that help receiving systems assess whether messages are authorized and aligned with the domain shown to recipients. They address different checks and work best as a coordinated setup. Authentication can support trust, but it does not guarantee inbox placement.
What SPF checks
Sender Policy Framework (SPF) lets a domain publish which sending systems are authorized for the domain used in the message’s envelope sender or sending host. The receiving system checks the connecting source against the domain’s DNS policy. SPF does not directly authenticate the visible From address a reader sees, and forwarding can affect the check.
What DKIM checks
DomainKeys Identified Mail (DKIM) adds a cryptographic signature to a message. The receiving system uses a public key published in DNS to verify that the signed parts of the message remain associated with the signing domain. A valid signature supports message integrity and identifies a signing domain, but the domain must still align appropriately with the visible sender for DMARC to pass.
What DMARC adds
Domain-based Message Authentication, Reporting, and Conformance (DMARC) connects authentication results to the domain in the visible From address. It requires alignment with either SPF or DKIM, lets the domain owner publish a policy for handling messages that fail, and can provide reports about sending sources.
Policies commonly move from monitoring toward stricter handling after legitimate senders are identified and alignment is checked. The exact rollout should fit the organization’s sending systems and risk. A strict policy applied before all legitimate sources are inventoried can disrupt wanted mail.
A careful setup sequence
- Inventory every system that sends mail using the domain, including marketing, billing, support, and application messages.
- Confirm the vendor’s current DNS requirements and publish authorized SPF and DKIM records.
- Verify the visible From domain aligns with a passing SPF or DKIM identity.
- Begin DMARC monitoring and review reports for legitimate and unexpected sources.
- Correct or remove unauthorized senders, then increase enforcement in a controlled way.
- Retest authentication after changing vendors, domains, or sending infrastructure.
DNS records require careful ownership and change management. Avoid copying a record from another organization or adding multiple SPF records for the same domain. Ask the sending provider and domain administrator to verify the correct values for your setup.
Authentication is one part of deliverability
Authenticated mail can still be filtered because reputation, complaint rates, list quality, recipient expectations, message content, and sending patterns also matter. The overview of email deliverability covers those factors, and the guide to diagnosing B2B email deliverability explains what to review before changing send volume.
SPF, DKIM, and DMARC answer related but different questions. Inventory senders, validate alignment, monitor results, and make policy changes only when the organization understands which legitimate messages could be affected.
How did this article land?
Choose one reaction. You can change it anytime.
