SPF, DKIM and DMARC Explained
What SPF, DKIM and DMARC actually do, how they work together to stop email spoofing, and the order to set them up — in plain English.
By the ToolsHub team · Updated May 1, 2026
SPF, DKIM and DMARC are three DNS records that together prove your email is really from you. Getting them right is what keeps your mail out of the spam folder and stops others from spoofing your domain. You can see all three for any domain at once with our free Email Deliverability Check.
SPF — who is allowed to send
SPF (Sender Policy Framework) is a list of the servers permitted to send email as your domain. When a message arrives, the receiver checks whether it came from a listed server. SPF has a strict limit of 10 DNS lookups — exceeding it silently breaks the record, which our SPF Checker flags.
DKIM — proof the message wasn't altered
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver fetches your public key from DNS and verifies the signature, proving the mail genuinely came from your domain and wasn't tampered with in transit. Check a domain's key with the DKIM Checker.
DMARC — what to do when checks fail
DMARC ties the two together. It tells receivers what to do with mail that fails both SPF and DKIM — monitor, quarantine, or reject — and asks them to send you reports about who is sending as your domain. Without DMARC you have no policy against spoofing and no visibility. See our DMARC Checker.
The order to set them up
Do SPF and DKIM first, since DMARC depends on them. Then publish DMARC at p=none to collect reports, confirm all your legitimate mail passes, and only then tighten to quarantine and finally reject. Jumping straight to reject is the classic way to start silently losing real email.
A sensible rollout order
Setting all three up at once can block your own mail. A safer sequence is:
- 1. SPF — publish one record listing every service that sends for your domain; check the lookup count with our SPF Checker.
- 2. DKIM — enable signing at your mail provider and confirm the public key with our DKIM Checker.
- 3. DMARC — start at
p=noneto monitor, then tighten to quarantine and reject once reports look clean.
Working in this order means legitimate mail keeps flowing while you build up to full enforcement and real protection against spoofing.
Frequently asked questions
- What are SPF, DKIM and DMARC?
- Three email authentication standards. SPF lists who may send mail for your domain, DKIM signs messages so tampering is detectable, and DMARC ties them together with a policy for failures.
- Do I need all three?
- For reliable delivery, yes. SPF and DKIM prove a message is legitimate, and DMARC tells receivers what to do when they aren't — together they curb spoofing and improve inbox placement.
- Which should I set up first?
- Start with SPF and DKIM so legitimate mail passes, then add DMARC in monitoring mode (p=none) to watch the results before enforcing. Our checkers and generators guide each step.
- How do I check if they're configured correctly?
- Use our SPF, DKIM and DMARC checkers to look up each record for your domain and see whether it's valid, with common problems flagged for you.