What Are DMARC, DKIM And SPF And Why Your Emails Need Them
If you have ever sent an email campaign and wondered why some of your messages ended up in spam folders, or worse, why your domain was being used by someone else to send fraudulent emails without your...

If you have ever sent an email campaign and wondered why some of your messages ended up in spam folders, or worse, why your domain was being used by someone else to send fraudulent emails without your knowledge, then the chances are that your email authentication setup is either incomplete or missing altogether. Understanding what DMARC, DKIM and SPF are, and why your emails genuinely need them, is no longer something you can afford to put off. These three protocols work together to protect your sending reputation, improve email deliverability, and give inbox providers the confidence they need to trust that your messages are legitimate.
Email fraud and phishing attacks are a growing problem across the internet, and without proper authentication in place, your domain is essentially an open invitation for bad actors to exploit. Let us break down exactly what each of these protocols does, how they work together, and what you need to do to get them in place.
What Is SPF And What Does It Actually Do?
SPF stands for Sender Policy Framework. In simple terms, it is a DNS record that you publish on your domain which tells the world which mail servers are authorised to send email on your behalf. When someone receives an email that claims to come from your domain, their mail server checks your SPF record to verify that the sending server is on your approved list.
Think of it like a guest list at an event. If a server tries to send email from your domain and it is not on your SPF record, the receiving server knows something is not right. Depending on how the receiving server is configured, it may reject that message outright or flag it as suspicious. SPF is published as a TXT record in your domain's DNS settings, and it lists all the IP addresses and services that are permitted to send on your behalf, whether that is your own mail server, a platform like Mailchimp or HubSpot, or any other third-party sending tool you use.
One thing worth knowing is that SPF does have limitations. It checks the envelope sender, which is a technical behind-the-scenes address, rather than the visible "From" address that your recipients see in their inbox. This is where DKIM comes into the picture.
What Is DKIM And Why Does It Matter?
DKIM stands for DomainKeys Identified Mail. Where SPF verifies which servers can send on your behalf, DKIM adds a cryptographic signature to your outgoing emails. This signature is generated using a private key held by your sending server, and a corresponding public key is published in your DNS records for anyone to check.
When a receiving mail server gets your email, it looks up your public DKIM key in your DNS, uses it to verify the signature attached to the message, and confirms that the email has not been tampered with in transit. It is a layer of integrity checking that proves two things: firstly, that the email genuinely originated from an authorised source connected to your domain, and secondly, that the content of the email has not been altered after it was sent.
Want more insights like this?
Join thousands of marketers getting weekly tips and strategies.
Without DKIM, even if SPF passes, there is no way for a receiving server to confirm the message has not been intercepted or modified along the way. Both protocols are doing different but complementary jobs, and you genuinely need both to build a solid authentication foundation.
What Is DMARC And Why Is It The Most Important Of The Three?
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. If SPF and DKIM are the checks, DMARC is the policy that tells receiving servers what to do when those checks fail, and it also provides you with reporting so you can see exactly what is happening with your domain's email traffic.
DMARC works by tying together SPF and DKIM results and applying alignment checks. For a DMARC check to pass, the domain in the visible "From" address needs to align with either the SPF domain or the DKIM signing domain. If neither aligns, DMARC fails, and then your DMARC policy kicks in to tell the receiving server how to handle that message.
You can set your DMARC policy to one of three settings. A policy of none means take no action but send me reports. A policy of quarantine means treat suspicious messages with caution, typically sending them to the spam folder. A policy of reject means block the message entirely and do not deliver it. Most professionals recommend starting with a none policy whilst you review your reporting data, and then gradually moving towards quarantine and eventually reject as you gain confidence that your legitimate email streams are all properly authenticated.
DMARC records are published in your DNS as TXT records, just like SPF, and they include an email address for receiving aggregate and forensic reports. Tools like Dmarcian and Valimail can help you make sense of the reporting data you receive, giving you a clear view of who is sending email using your domain.
How Do SPF, DKIM And DMARC Work Together?
These three protocols are designed to be used in combination, not in isolation. SPF establishes which servers are authorised. DKIM provides a cryptographic signature that proves authenticity and integrity. DMARC ties the results together, enforces your chosen policy, and gives you visibility through reporting. On their own, each protocol offers partial protection. Together, they create a robust authentication framework that significantly reduces the risk of your domain being used for phishing, spoofing or email fraud.
It is also worth noting that major inbox providers, including Google and Yahoo, have updated their requirements for bulk senders. As of 2024, Google now requires that anyone sending large volumes of email to Gmail addresses has SPF, DKIM and a DMARC policy in place. Failing to meet these requirements can result in your emails being rejected or heavily filtered, which has a direct impact on your marketing performance and business communications alike.
What Happens If You Do Not Have These In Place?
Without proper email authentication, several things can go wrong. Your legitimate emails are far more likely to land in spam folders because inbox providers have no way of verifying that your messages are genuine. Your domain becomes a more attractive target for spoofing, where fraudsters send emails pretending to be you without your knowledge or consent. And if your domain does get used in phishing campaigns, the reputational damage to your brand can be significant and difficult to recover from.
From a marketing perspective, poor deliverability means your campaigns simply do not reach the people they are supposed to reach. You might be spending considerable time and budget creating great email content, but if the technical foundations are not in place, a portion of that work is effectively wasted before anyone even opens the message.
Getting Your Authentication Set Up Correctly
The good news is that setting up SPF, DKIM and DMARC is entirely achievable, though it does require access to your domain's DNS settings and some careful planning if you use multiple platforms to send email. You will need to identify every service that sends email on your domain's behalf, whether that is your CRM, your email marketing platform, your helpdesk software or your transactional email provider, and make sure each one is properly covered by your SPF and DKIM configuration.
A useful starting point is the MXToolbox suite of free tools, which allows you to check your existing SPF, DKIM and DMARC records and identify any issues. From there, you can work through each element methodically, publish your DMARC record in monitoring mode, review the reports as they come in, and tighten your policy over time as you gain a clearer picture of your email ecosystem.
Why This Matters More Than Ever
Email remains one of the highest-returning channels in digital marketing, but it is only effective if your messages actually reach the inbox. DMARC, DKIM and SPF are no longer optional extras or something to consider at a later date. They are fundamental requirements for any business that relies on email as part of its communications or marketing strategy.
Getting these protocols properly configured protects your domain, safeguards your recipients from fraud, improves your deliverability, and ensures that the email work you invest in actually reaches the people it is meant for. If you have not yet reviewed your email authentication setup, now is the right time to do it.
Ian
Ian has worked in Digital Marketing for decades, and is a Google Partner for Google Ads and an expert in onsite and technical SEO. He has worked with hundreds of clients, helping them achieve success online, through SEO, PPC and Digital Marketing, working with local businesses through to national retailers.
View all posts →Related Articles

6 Simple Ways To Boost Your Mailing List
As more and more business come back to the realisation that email marketing, if done correctly, still works, the power of making it successful is through relevant subscribers and constantly growing them to expand your reach.

Guide To Email Marketing In 2026
Email marketing in 2026 isn't just about sending newsletters and hoping for the best. The landscape has evolved dramatically, with AI-powered personalisation, privacy regulations, and shifting consume...

Why Email Marketing Can Still Be A Powerful Source Of Leads
In a world dominated by flashy social media campaigns and cutting-edge marketing automation, email marketing might seem as outdated as a the first mobile phone. Yet, it can still work.
