Learn / updated 2026-10-04
SPF, DKIM and DMARC explained: how e-mail authentication works
Anyone can type any address in the "From" line of an e-mail. SPF, DKIM and DMARC are three DNS-based checks that let a receiving server decide whether a message really comes from the domain it claims.
SPF: who may send
An SPF record is a TXT record on the domain that lists the servers allowed to send its mail, for example v=spf1 include:_spf.example.net ip4:203.0.113.5 -all. The receiver compares the sending server with the list. The ending matters: -all means "reject everything else", ~all means "treat everything else as suspicious". An SPF record may trigger at most ten DNS lookups; going over that limit makes the check fail.
DKIM: was the message altered
DKIM adds a cryptographic signature to each message. The public key lives in DNS under a name that includes a selector, such as selector1._domainkey.example.com. The receiver uses it to check that the signed parts of the message were not changed and that the signing domain approved it. Because the selector name is chosen by the sender, you cannot discover a DKIM key from the domain name alone.
DMARC: what to do when checks fail
A DMARC record (a TXT record at _dmarc.example.com) ties the two together. It requires that the domain in the visible "From" address aligns with the domain that passed SPF or DKIM, and it tells receivers what to do otherwise: p=none (only report), p=quarantine (treat as suspicious) or p=reject (refuse). It can also name an address for aggregate reports (rua=).
Common mistakes
- Several SPF records on one domain (only one is allowed).
- Forgetting a service that sends on your behalf, so its mail fails.
- Starting DMARC at
p=rejectwithout reading the reports first. A safer path isnone, thenquarantine, thenreject. - Assuming DKIM is set up because SPF passes.
Checking a domain
The free SPF and DMARC checker shows whether SPF and DMARC are present, their policies and the domain's mail and name-server records. DKIM cannot be checked without the selector.
Frequently asked questions
Do I need all three? Mailbox providers increasingly expect SPF and DKIM, and DMARC ties them together and gives you reports; large senders are required to have them.
Does DMARC stop spoofing of my domain? With p=reject and aligned senders it makes spoofing of the exact From domain much harder; it does not stop look-alike domains.
Related
- DNS Lookup: API reference
- CPV codes and OCDS explained: how public tenders are described
- How EU VAT number validation works (VIES explained)
- What is an LEI (Legal Entity Identifier)? Format, use and lookup
- What is an SSL/TLS certificate, and why does expiry matter?
- All tools and prices
Informational only, not financial, legal or tax advice.