Question

What are SPF, DKIM and DMARC?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Three DNS-published records that together let a receiving mail server answer one question: was this message really sent by the domain it claims to come from? Email was designed with no sender authentication at all, and these were bolted on afterwards to address that.

SPF (Sender Policy Framework). A DNS TXT record listing which servers are permitted to send mail for your domain. The receiver checks whether the connecting server's IP appears in it.

Its weakness: SPF validates the envelope sender, not the visible From address, and it breaks on forwarding — a forwarded message arrives from a server not on the list.

DKIM (DomainKeys Identified Mail). The sending server cryptographically signs the message with a private key; the public key is published in DNS. The receiver verifies the signature, proving the message was signed by the domain and has not been altered in transit.

Its weakness: it proves the signing domain, which need not be the domain a human sees in the From line.

DMARC. The piece that makes the other two useful. It does three things:

Alignment — it requires that the domain validated by SPF or DKIM matches the visible From domain, closing the gap both leave open.

Policy — it tells receivers what to do when a message fails: none (monitor only), quarantine (spam folder), or reject.

Reporting — receivers send aggregate reports showing who is sending as your domain, which is how you discover both spoofing and your own forgotten systems.

Why this is no longer optional. Major mailbox providers now require authentication for bulk senders, and unauthenticated mail is increasingly rejected outright.

The usual failure mode is deploying p=reject before reviewing reports, which blocks legitimate mail from third-party senders — newsletter platforms, invoicing tools, booking systems — that nobody remembered were sending as the domain. Start at p=none, read the reports, then tighten.

Related Questions