ambolt

Learn / updated 2026-10-04

SPF, DKIM and DMARC explained: how e-mail authentication works

Anyone can type any address in the "From" line of an e-mail. SPF, DKIM and DMARC are three DNS-based checks that let a receiving server decide whether a message really comes from the domain it claims.

SPF: who may send

An SPF record is a TXT record on the domain that lists the servers allowed to send its mail, for example v=spf1 include:_spf.example.net ip4:203.0.113.5 -all. The receiver compares the sending server with the list. The ending matters: -all means "reject everything else", ~all means "treat everything else as suspicious". An SPF record may trigger at most ten DNS lookups; going over that limit makes the check fail.

DKIM: was the message altered

DKIM adds a cryptographic signature to each message. The public key lives in DNS under a name that includes a selector, such as selector1._domainkey.example.com. The receiver uses it to check that the signed parts of the message were not changed and that the signing domain approved it. Because the selector name is chosen by the sender, you cannot discover a DKIM key from the domain name alone.

DMARC: what to do when checks fail

A DMARC record (a TXT record at _dmarc.example.com) ties the two together. It requires that the domain in the visible "From" address aligns with the domain that passed SPF or DKIM, and it tells receivers what to do otherwise: p=none (only report), p=quarantine (treat as suspicious) or p=reject (refuse). It can also name an address for aggregate reports (rua=).

Common mistakes

Checking a domain

The free SPF and DMARC checker shows whether SPF and DMARC are present, their policies and the domain's mail and name-server records. DKIM cannot be checked without the selector.

Frequently asked questions

Do I need all three? Mailbox providers increasingly expect SPF and DKIM, and DMARC ties them together and gives you reports; large senders are required to have them.

Does DMARC stop spoofing of my domain? With p=reject and aligned senders it makes spoofing of the exact From domain much harder; it does not stop look-alike domains.

Related

Informational only, not financial, legal or tax advice.