SPF, DKIM and DMARC, in plain terms
Email was invented when everyone trusted everyone: anybody can write “From: you@your-domain.com” on an envelope. These three settings, published in your domain's DNS, let receiving servers check that a message really comes from you.
01
SPF
The list of authorized mail carriers. You publish which servers may send email for your domain: your mailbox provider, your newsletter tool, your invoicing software.
Limit: SPF checks the message's technical envelope, not the address the recipient sees. And it breaks when a message is forwarded.
02
DKIM
The wax seal. Every message leaves with an encrypted signature; the key to verify it is published in your DNS. If someone alters the message on the way, the seal breaks.
Every service sending on your behalf needs its own key, identified by a “selector”.
03
DMARC
The instructions for the post office. They say what to do with a message that claims to be from you but fails SPF and DKIM: let it through, send it to spam, or reject it.
As a bonus, major providers send you a daily report of everything that went out under your name.
The key point, often misunderstood: DMARC requires alignment. It isn't enough for SPF or DKIM to pass; they must pass for the same domain shown in the “From:”. A newsletter signed with its provider's domain instead of yours passes DKIM… but fails DMARC.
Why it became mandatory
Since February 2024, Gmail and Yahoo reject or send to spam messages from poorly configured domains. Microsoft (Outlook, Hotmail) has applied similar rules to bulk senders since May 2025. Small organizations are affected too: a newsletter to 800 members, donation receipts, a website's automatic notices.
For all senders
- Valid SPF or DKIM
- Correct reverse DNS (PTR) for sending servers
- Encrypted connection (TLS)
- Spam complaint rate under 0.3%
Above 5,000 messages a day
- SPF and DKIM
- DMARC published, at least
p=none
- “From:” domain aligned with SPF or DKIM
- One-click unsubscribe for bulk mail
Even below those volumes, setting everything up is the best delivery insurance: filters treat a clearly identified domain better.
In what order
- List everything that sends on your behalf. Your mailbox provider (Google, Microsoft…), the newsletter tool, invoicing, ticketing, your WordPress site's forms, your membership software. This is the step people skip, and it causes most problems.
- Publish a single SPF authorizing all of them, staying under 10 DNS lookups. End it with
~all.
- Turn on DKIM at each service, using your own domain. Each one provides one or two records to add to your DNS.
- Publish DMARC in monitoring mode:
p=none with a rua= address to receive reports.
- Read the reports for two to four weeks. They show every sending source. Fix the ones that fail: often a service forgotten in step 1.
- Tighten:
p=quarantine, then p=reject once everything passes. Your name is then protected against phishing.
The most common mistakes
Two SPF records
A new service says “add this SPF”, and it gets added next to the old one. With two SPF records, both are invalid. They must be merged into one.
More than 10 DNS lookups
Each include: often hides others. You go over the limit without noticing, and the whole SPF fails. Our counter does the math for you.
The website's form, forgotten
A WordPress site sending “From: info@your-domain.com” from its host, without the host being in SPF or signing with DKIM: contact or order messages land in spam. The fix is an authenticated SMTP relay, or adding the host to SPF with a DKIM key.
Staying at p=none forever
DMARC in monitoring mode meets the requirements but protects nothing. Fraudsters can keep writing to your members or customers in your name.
A 1024-bit DKIM key never renewed
Still accepted, but no longer the recommendation. Use a key rotation to move to 2048 bits.
Finding your DKIM selector
Unlike SPF and DMARC, which live at fixed addresses, a DKIM key is published under a name each service picks. We try the most common ones, but yours may differ. To find it:
- Send yourself an email from the service to check (your mailbox, your newsletter tool…) to a Gmail address.
- Show the original. In Gmail: the message's ⋮ menu, then “Show original”. In Outlook: “View message source”.
- Look for the
DKIM-Signature line. The selector is the s= value, the domain the d= value. For example d=example.com; s=k1;.
- Enter the selector in the check options at the top of this page.
If d= isn't your domain (say d=mcsv.net), the service signs with its own domain: DKIM passes, but DMARC alignment doesn't. Look in its settings for an “authenticate your domain” option.
Frequently asked questions
Everything is green, but my emails still go to spam. Why?
SPF, DKIM and DMARC prove you are who you say; they don't say whether your messages are wanted. The reputation of the domain and sending servers weighs heavily: a domain once used for spam (or hacked) can stay penalized for months. Content, links, complaints and sudden volume spikes matter too. For Gmail, the free Google Postmaster Tools shows your domain's reputation.
~all or -all?
With DMARC in place, both work: the DMARC policy decides what happens to messages. ~all is more forgiving of forwarded mail (a message redirected by another mailbox fails SPF). -all is stricter. Start with ~all, move to -all if you like, once everything is checked.
Does a domain that sends no email need DMARC?
Yes, and that's where it's simplest: v=spf1 -all for SPF and v=DMARC1; p=reject for DMARC. Fraudsters love dormant domains, because nobody watches them.
Are my subdomains covered?
For DMARC, yes: without its own record, a subdomain follows the main domain's (its sp= value, or p=). For SPF and DKIM, no: each sending subdomain needs its own.
How long before a DNS change shows up?
Often a few minutes, sometimes a few hours, depending on the record's time to live (TTL). If our tool still shows the old version, try again a little later.
What do you do with the domains checked?
Nothing: the check runs live, and the result isn't stored. We only keep, for at most two hours, an encrypted fingerprint of your IP address to limit abuse. Details in our privacy policy (in French).