Guide
SPF, DKIM and DMARC, in plain English.
Three records on your domain decide whether your quotes and invoices reach inboxes, and whether someone else can send email pretending to be you. Here is what each one does, how to set them up, and what usually goes wrong.
- SPF: who may send
- DKIM: a signature
- DMARC: what to do if both fail
Why it matters.
Anyone can send an email that claims to come from your domain. Nothing in email itself stops them. SPF, DKIM and DMARC are how the receiving mail server tells a genuine message from a forgery, and they are now a basic requirement rather than a nice extra.
Since February 2024, Gmail and Yahoo have required every sender to have SPF or DKIM in place, and anyone sending more than 5,000 messages a day to Gmail to have all three, including DMARC. Microsoft brought in similar rules for high-volume senders to Outlook.com in 2025. Even a small business sending a handful of emails a day is judged partly on these records.
When they are missing or wrong, two things happen. Your genuine email is more likely to land in spam, and it is easier for a scammer to send fake invoices in your name to your own customers.
The three records at a glance.
| Record | Where it lives | What it does |
|---|---|---|
| SPF | A TXT record on your domain itself | Lists the services allowed to send email for your domain. |
| DKIM | A TXT or CNAME record at selector._domainkey | Publishes the key that checks the digital signature on each message you send. |
| DMARC | A TXT record at _dmarc | Tells receivers what to do when a message fails SPF and DKIM, and where to send reports. |
SPF: who is allowed to send.
SPF is one TXT record that lists every service allowed to send email as your domain. For Microsoft 365 it usually looks like this:
v=spf1 include:spf.protection.outlook.com -allAnd for Google Workspace:
v=spf1 include:_spf.google.com ~allEvery other service that sends as your domain needs adding too: your newsletter tool, your accounts software if it emails invoices, and your website if its contact form sends mail through your domain. The ending decides what happens to everything else: -all means reject, ~all means treat with suspicion.
The usual mistakes:
- Two SPF records. A domain may only have one. Two makes both invalid. Merge them into a single record.
- Too many lookups. SPF allows at most 10 DNS lookups. Each
include:counts, and so do the includes inside it. Past 10, SPF fails. - A forgotten sender. Invoices from your accounts software quietly going to spam is usually a missing include.
DKIM: a signature on every email.
DKIM adds a digital signature to each message you send. The receiving server looks up your public key in DNS and checks the signature, which proves the message came from an authorised service and was not changed on the way.
You do not write DKIM records by hand. Your email service generates them:
- Microsoft 365: two CNAME records,
selector1._domainkeyandselector2._domainkey, pointing at Microsoft. Once they are published, you switch DKIM signing on in the Microsoft Defender portal. - Google Workspace: generate a key in the Admin console under Apps, Google Workspace, Gmail, Authenticate email. Publish it as a TXT record at
google._domainkey, then click Start authentication.
Every other service that sends as your domain, such as a newsletter tool, has its own DKIM record to add. Without it, those messages are signed with the service’s domain instead of yours, which does not count for DMARC.
DMARC: what to do when both fail.
DMARC ties the other two to the address your recipient actually sees in the From line. A message passes when SPF or DKIM passes for that same domain. DMARC then tells receivers what to do with messages that fail, and where to send reports about them.
Start by watching, not blocking:
Host: _dmarc
Type: TXT
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.ukp=none changes nothing about delivery. It just asks receivers to send daily reports to the rua address, showing every service sending as your domain and whether it passes. Those reports arrive as XML files, so a free or cheap report service that turns them into something readable is worth using.
Once the reports show everything genuine passing, usually after a few weeks, move to p=quarantine, which sends failures to spam, and then to p=reject, which refuses them outright. That last step is what actually stops someone sending email as you.
The most common DMARC mistake is setting p=none and never looking at it again. The second is jumping straight to p=reject and blocking your own invoices.
How to check yours.
You can look up your own records from a Windows command prompt:
nslookup -type=txt yourdomain.co.uk
nslookup -type=txt _dmarc.yourdomain.co.ukOr on a Mac or Linux terminal:
dig +short TXT yourdomain.co.uk
dig +short TXT _dmarc.yourdomain.co.ukIf there is no line starting v=spf1 in the first result, you have no SPF. If the second returns nothing, you have no DMARC. Checking DKIM needs the selector name, which is in the headers of any email you have sent.
Or ask us for a free check: we look at all three, along with your website’s speed and SEO basics, and tell you in plain English what we would fix first.
Email security questions
Ask us something else →Do I need all three?
Yes. SPF and DKIM each prove something different, and DMARC is what makes receivers act on them. Gmail and Yahoo already require at least SPF or DKIM from every sender, and all three from bulk senders.
Will DMARC stop my own emails arriving?
Not at p=none, which only collects reports. It can at p=quarantine or p=reject if a genuine service is not set up properly, which is why you watch the reports before tightening the policy.
Do these records stop phishing emails reaching me?
Not directly. They stop other people sending email as your domain. Filtering the phishing that arrives in your own inbox is your email provider’s job, though it also uses other senders’ SPF, DKIM and DMARC to do it.
What about emails from my website’s contact form?
Those are sent by your website’s server, not your mailbox. They need to go through an authenticated email service that is included in your SPF and signs with DKIM for your domain, or they are likely to be treated as forgeries.
How long do changes take?
Usually minutes. DNS changes can take up to 48 hours to reach everywhere, depending on the record’s time to live.
Is this included in IT Care?
Yes. Every IT Care plan sets up SPF, DKIM and DMARC and monitors them, and the Braw website plan includes business email set up properly.
Not sure about yours?
Send us your domain and we will check SPF, DKIM and DMARC for free, along with your website’s speed and SEO basics.
Get a free email check →