Email · 5 min read

SPF, DKIM and DMARC Explained

What SPF, DKIM and DMARC actually do, how they work together to stop email spoofing, and the order to set them up — in plain English.

By the ToolsHub team · Updated May 1, 2026

SPF, DKIM and DMARC are three DNS records that together prove your email is really from you. Getting them right is what keeps your mail out of the spam folder and stops others from spoofing your domain. You can see all three for any domain at once with our free Email Deliverability Check.

SPF — who is allowed to send

SPF (Sender Policy Framework) is a list of the servers permitted to send email as your domain. When a message arrives, the receiver checks whether it came from a listed server. SPF has a strict limit of 10 DNS lookups — exceeding it silently breaks the record, which our SPF Checker flags.

DKIM — proof the message wasn't altered

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver fetches your public key from DNS and verifies the signature, proving the mail genuinely came from your domain and wasn't tampered with in transit. Check a domain's key with the DKIM Checker.

DMARC — what to do when checks fail

DMARC ties the two together. It tells receivers what to do with mail that fails both SPF and DKIM — monitor, quarantine, or reject — and asks them to send you reports about who is sending as your domain. Without DMARC you have no policy against spoofing and no visibility. See our DMARC Checker.

The order to set them up

Do SPF and DKIM first, since DMARC depends on them. Then publish DMARC at p=none to collect reports, confirm all your legitimate mail passes, and only then tighten to quarantine and finally reject. Jumping straight to reject is the classic way to start silently losing real email.

Try the tool