Back to Blog

SPF, DKIM and DMARC Explained: Setup Guide

SPF, DKIM and DMARC explained: how these DNS records keep your email out of spam, what each record looks like, how to set them up and mistakes to avoid.

Nodesty Team6 min readEmail
The words SPF, DKIM and DMARC with MX, TXT and DNS on a dark Nodesty background

SPF, DKIM and DMARC are three DNS records that prove to receiving mail servers that an email really comes from your domain. SPF lists the servers allowed to send email for your domain, DKIM adds a digital signature to every message and DMARC tells the receiver what to do when those checks fail. If they are missing or wrong, your email lands in spam or is rejected outright, and anyone can send convincing fake email in your name.

This guide explains how each record works, shows what they look like, walks through the setup step by step and lists the mistakes we see most often.

Why email authentication matters

Email was designed in the 1980s without any way to check who the sender really is. Anyone can put any address in the "From" field, the same way anyone can write any return address on an envelope. Most phishing relies on exactly that.

SPF, DKIM and DMARC fix this through DNS. The domain owner publishes who may send email for the domain and how that email is signed, and the receiving server checks every incoming message against those records.

These records are no longer optional. Since February 2024, Gmail and Yahoo require at least SPF or DKIM from everyone who sends to their users, and SPF, DKIM and DMARC together from anyone sending more than 5,000 messages a day. Microsoft applies similar rules to Outlook.com.

What is SPF?

SPF (Sender Policy Framework) is a list of the servers allowed to send email on behalf of your domain. It is published as a TXT record on the domain. When a receiving server gets a message, it checks whether the sending server's IP address is on that list.

A typical SPF record:

yourcompany.com.  TXT  "v=spf1 include:_spf.example-provider.com ip4:203.0.113.10 ~all"

What each part means:

  • v=spf1 marks this as an SPF record.
  • include:... pulls in another service's list of servers, such as your mail hosting provider's.
  • ip4:... allows a specific IP address, for example a VPS you send email from.
  • ~all asks receivers to treat mail from any other server as suspicious. -all asks them to reject it.

SPF has two important limits. A domain can have only one SPF record; two separate v=spf1 records break SPF entirely. And an SPF check may trigger at most 10 DNS lookups; add too many include mechanisms and SPF returns an error.

SPF is not enough on its own, because it only checks the server that delivered the message. Forwarding can break it, and it does not directly protect the "From" address the reader sees. DKIM and DMARC close those gaps.

What is DKIM?

DKIM (DomainKeys Identified Mail) is a digital signature added to every message you send. The sending server signs the headers and body with a private key, and the matching public key is published in your domain's DNS. The receiving server uses the public key to check the signature. If it matches, the message really came from your servers and was not changed in transit.

A DKIM record is published under a selector on the _domainkey subdomain:

default._domainkey.yourcompany.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."

You do not create the key yourself. Your email service generates it and shows you the value to add to DNS. Thanks to selectors, one domain can have several DKIM keys, for example one for your mail hosting and one for your newsletter tool.

DKIM survives forwarding much better than SPF, because the signature travels with the message itself.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together. It does two things:

  1. It checks alignment. The domain in the visible "From" address must match the domain that passed SPF or DKIM. That stops an attacker from passing SPF with their own domain while putting yours in the "From" field.
  2. It sets a policy and asks for reports. It tells receivers what to do with messages that fail, and asks them to send you reports.

The DMARC record lives on the _dmarc subdomain:

_dmarc.yourcompany.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com"

The p value is the policy:

  • p=none: take no action, just report. The right place to start.
  • p=quarantine: send failing messages to spam.
  • p=reject: reject failing messages.

The rua address receives daily aggregate reports showing who sends email for your domain and whether it passes. The reports are XML, so use one of the free DMARC report analyzers to read them.

How to set up SPF, DKIM and DMARC

  1. List every service that sends email for your domain. Your mail hosting, your website's contact form, your invoicing system, your newsletter tool, your CRM. Forgetting one of these is the most common mistake.
  2. Set your MX records. MX records decide which server receives your incoming email. Enter the values from your mail hosting provider and remove old MX records.
  3. Create a single SPF record. Combine the include value of every service in one v=spf1 record and end it with ~all.
  4. Enable DKIM. Turn on DKIM signing in each service and add the TXT record it gives you. Adding the record is not enough on its own; check that signing is actually switched on.
  5. Add DMARC with p=none and choose an address for reports.
  6. Test. Send a message to yourself and to a Gmail address. In Gmail, "Show original" lists SPF, DKIM and DMARC as PASS or FAIL. mail-tester.com scores all records in one go.
  7. Tighten the policy. Once the reports show every legitimate service passing for a few weeks, move to p=quarantine, then to p=reject.

Common mistakes

  • Two SPF records. Adding a second v=spf1 record for a new service instead of editing the existing one. SPF then fails completely.
  • Going over 10 lookups. Every include costs at least one lookup and may contain more. Remove services you no longer use.
  • Using +all. It allows every server in the world to send as you, which makes SPF pointless.
  • Mangling the DKIM key. Long DKIM values sometimes get split or picked up with trailing spaces in DNS panels. Verify the record with a DKIM checker after adding it.
  • Starting with p=reject. If you forgot a service, such as your invoicing system, its email is rejected and you only find out when customers complain.
  • Sending bulk mail from your business mailbox. Correct records do not fix the reputation damage of mass mailing. Use a service built for newsletters and campaigns.

Authentication is only part of deliverability

Good inbox placement is close to impossible today without SPF, DKIM and DMARC, but they are not enough on their own. Receiving providers also look at the history of the sending IP and domain, message content, blocklists and whether recipients mark your messages as spam. A correct reverse DNS (rDNS) record for the sending IP matters too; on mail hosting, your provider sets that for you.

On Nodesty mail hosting, the MX, SPF and DKIM values you need are shown ready to copy in the panel, along with whether each record has been verified. Incoming mail is filtered by SpamExperts, and you can read your email in webmail or over IMAP and POP3. To protect the reputation of our IP addresses, bulk email is not allowed.

Frequently Asked Questions

Do I need all three of SPF, DKIM and DMARC?

Yes. SPF and DKIM verify the sender in two different ways, and DMARC tells receivers what to do when those checks fail. Gmail and Yahoo require at least SPF or DKIM from every sender, and all three from anyone sending more than 5,000 messages a day.

Can a domain have more than one SPF record?

No. A domain must have exactly one SPF record. Two separate v=spf1 records make SPF fail with an error. If you use several services, combine them in a single record with include mechanisms.

How long do the DNS records take to work?

Most DNS changes spread within minutes to a few hours, but depending on the record's TTL and your DNS provider it can take up to 24 hours. You can check whether a record is visible with a lookup tool such as MXToolbox.

Should I start with p=reject?

No. Start with p=none and read the reports for a few weeks. Once every service that sends email for your domain passes SPF or DKIM, move to p=quarantine and then to p=reject. Otherwise you risk blocking your own legitimate email.

My records are correct, so why does my email still go to spam?

Authentication is only part of deliverability. The reputation of the sending IP and domain, message content, blocklists and the recipient provider's own filters also play a role. A tool like mail-tester.com shows where you are losing points.

Do I need these records for email sent from web hosting?

Yes. Whichever service sends your email, your domain's SPF, DKIM and DMARC records need to cover it. If you send from both web hosting and a separate mail hosting service, include both in your SPF record.

Nodesty

About the author

Nodesty Team · Infrastructure & Support

The Nodesty team runs our servers, network and DDoS protection day to day and answers customer support requests around the clock. These guides come from that work.

Related articles

Launch your server now.

Build, scale, and conquer without limits on Nodesty's premium infrastructure.

                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
                                                                                                                             ············································                                                   
                                                ··································································································..........···························                                     
                                       ················..........................................................................................................................··············                             
                                  ·············.................::::::::::::::::::::::::::::::::::::::::::::::....................:::::::::::::::::::::::::::::::::::::::................···········                        
                             ············................:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::............·········                     
                         ············.................:::::::::::::::::::::::::::::::::::::::::::::::::::------------::::::::::::::::::::::::::::::----------------:::::::::::::::::::::..........········                  
                    ············......................::::::::::::::::::::::::::::::::::::------------------------------------------------------------------------------------:::::::::::::.........········                
                ··········.............................................::::::::::::::::::-------------==========================================-----------------------------------:::::::::::........·······               
             ········..................:.....................................::::::::::--------=======+++++++++++++++++++++++++++++++++++++=========================------------------::::::::::.......·······              
           ······.........::::::::::::::::::::................................:::::::-----=====++++xxxxxx**************************xxxxxxxxx++++++++++++++===================------------::::::::.......·······             
          ·····.......:::::::::::::::::::::::::::.............................:::::----===+++xxx****%%%%&&&&&&#############&&&&&&&%%%%%*******xxxxxxxx++++++++++++++==============----------:::::::......······             
         ····......::::::::-------------:::::::::::..........................::::---===+++xx***%%%&&&####@@@@@@@@@@@@@@@@@@@@@@@@####&&&&&%%%%*******xxxxxxxxx+++++++++++++===========--------::::::......·····             
        ····.....:::::::--------------------:::::::::.......................::::---===++xxx**%%&&&###@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@###&&&&%%%%%********xxxxxxxxxxx++++++++++++========------::::::.....······            
        ····.....:::::--------------------------::::::::....................::::---===++xx***%%&&&####@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@###&&&&&%%%%%**********xxxxxxxxxxxxx+++++++++=======------:::::.....·····            
        ····....::::::-------=============---------:::::::::................:::::---===+++xx***%%%&&&#####@@@@@@@@@@@@@@@@@@@@@@@@@#####&&&&&%%%%%%*************xxxxxxxxxxxxxx+++++++++======-----:::::....·····            
         ····....:::::-------================---------:::::::::...............:::::----===++++xxx***%%%%&&&&&&#################&&&&&&%%%%%%%*******************xxxxxxxxxxxxxxxxx++++++++======----:::::....·····            
         ·····....:::::--------=================---------::::::::::..............:::::::-----====+++++xxxxxx**************************xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx++++++++=====-----::::....·····            
          ·····.....:::::--------=================----------:::::::::::.................:::::::::-------=============++++++++++++++++++++++++++++++++++++xxxxxxxxxxxxxxxxxxxxxxx++++++++======-----::::....·····            
            ·····.....:::::::----------===========-------------::::::::::::.........................::::::::::::::::::------------------=============+++++++++++++++++++++++++++++++++=======-----::::.....·····            
              ······......:::::::---------------------------------:::::::::::::........................................:::::::::::::::-----------============+++++++++++++++++++++========------:::::.....·····             
                 ······........:::::::::---------------------------:::::::::::::::::...........................................:::::::::::::------------=============================--------::::::.....······              
                    ·········.........:::::::::::::::-------------::::::::::::::::::::::::.......................................::::::::::::::::--------------------------------------::::::::......·······                
                          ··········............::::::::::::::::::::::::::::::::::::::::::::::::::................................::::::::::::::::::::::::::-------------:::::::::::::::.........········                   
                                  ············..................:::::::::::::::::::::::::::::::::::::::::::.........................:::::::::::::::::::::::::::::::::::::................···········                        
                                             ················.............................................................................................................·················                                 
                                                           ······················................................................................···························                                                
                                                                               ·········································································