Back to email
email

What Are SPF, DKIM And DMARC And Why Your Emails Need Them

If you have ever sent an email campaign, set up a business email account, or wondered why some of your emails end up in the spam folder rather than the inbox, then understanding SPF, DKIM and DMARC is...

July 20, 2026
7 min read
What Are SPF, DKIM And DMARC And Why Your Emails Need Them

If you have ever sent an email campaign, set up a business email account, or wondered why some of your emails end up in the spam folder rather than the inbox, then understanding SPF, DKIM and DMARC is something you simply cannot afford to ignore. These three protocols sit quietly in the background of your email infrastructure, working together to protect your domain, authenticate your messages, and tell the world's mail servers that your emails are legitimate. Yet despite how critical they are, a huge number of businesses either have them misconfigured, partially set up, or missing altogether. This guide breaks down what SPF, DKIM and DMARC actually are, how they work, and why getting them right matters enormously for your email deliverability and your brand reputation.

The Problem With Email Authentication

Email, by its original design, was never built with security in mind. When the protocols that underpin email were developed, the internet was a very different place, and the ability for someone to send a message pretending to be from your domain was not considered a significant risk. Fast forward to today, and email spoofing, phishing attacks, and domain impersonation are among the most common threats businesses face. Without proper authentication in place, anyone can technically send an email that appears to come from your domain, which not only puts your customers at risk but can cause catastrophic damage to your sending reputation and your brand. SPF, DKIM and DMARC exist to address exactly this problem, and they do so in three distinct but complementary ways.

What Is SPF?

SPF stands for Sender Policy Framework. In simple terms, it is a DNS record that you publish on your domain which tells receiving mail servers which IP addresses and sending services are authorised to send email on your behalf. When an email arrives claiming to be from your domain, the receiving server checks your SPF record to verify whether the sending server is on your approved list. If it is not, the email can be flagged, quarantined, or rejected.

Setting up an SPF record involves adding a TXT record to your domain's DNS settings. A basic SPF record might authorise your own mail server, your email marketing platform such as Mailchimp or Klaviyo, and any third-party services that send transactional emails on your behalf. It is worth noting that SPF alone has its limitations. It only checks the sending IP address, and it does not survive email forwarding particularly well. This is why SPF should always be used alongside DKIM and DMARC rather than as a standalone solution.

What Is DKIM?

Want more insights like this?

Join thousands of marketers getting weekly tips and strategies.

DKIM stands for DomainKeys Identified Mail. Where SPF verifies the sending server, DKIM works differently by attaching a digital signature to every email you send. This signature is generated using a private key stored securely on your sending server or email service, and it corresponds to a public key that you publish in your DNS records. When a receiving mail server gets your email, it retrieves your public key from DNS and uses it to verify the signature. If the signature checks out, the server knows the email genuinely originated from your domain and has not been tampered with in transit.

One of the real strengths of DKIM is that it also protects the content of your emails. If someone were to intercept and modify a message between sending and delivery, the DKIM signature would fail validation, alerting the receiving server that something is not right. Most reputable email service providers will guide you through the process of enabling DKIM, and platforms like Google Workspace and Microsoft 365 make configuring DKIM relatively straightforward within their admin dashboards.

What Is DMARC?

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is the layer that ties SPF and DKIM together and gives you control over what happens when an email fails authentication checks. A DMARC policy, published as a DNS TXT record, tells receiving mail servers what action to take if an email claiming to be from your domain fails both SPF and DKIM verification. The three policy options are none, quarantine, and reject.

A policy of none means no action is taken but reports are still generated, which is useful when you are first getting set up and want to understand your email traffic before enforcing rules. Quarantine instructs receiving servers to move failing emails to the spam folder. Reject is the strictest setting and tells servers to block those emails entirely. DMARC also includes a powerful reporting mechanism. You can specify an email address in your DMARC record to receive aggregate and forensic reports, giving you visibility into who is sending email using your domain and whether authentication is passing or failing. Tools like Dmarcian or MXToolbox can help you interpret these reports and manage your DMARC configuration over time.

Why These Three Protocols Work Together

It is tempting to think that setting up just one of these records is enough, but the reality is that SPF, DKIM and DMARC are most effective when all three are implemented correctly. SPF tells servers who is allowed to send on your behalf. DKIM proves the email genuinely came from you and was not altered. DMARC tells servers what to do when either of those checks fails, and it reports back to you so you always know what is happening with your domain's email activity. Without DMARC, even if SPF and DKIM are in place, there is no enforcement mechanism. Without DKIM, SPF alone cannot protect against header spoofing. Each element fills a gap that the others leave open.

The Impact On Email Deliverability

Beyond the security benefits, there is a very practical reason why email marketers and business owners need to take these protocols seriously. In February 2024, Google announced that senders emailing Gmail accounts at scale must have SPF and DKIM authentication in place, along with a DMARC policy, or risk having their messages rejected. Yahoo made similar announcements around the same time. This is a clear signal from the industry's largest email providers that authentication is no longer optional. It is now a baseline requirement for anyone who wants their emails to reach the inbox reliably.

Poor authentication can result in emails being filtered to spam, a drop in open rates, damage to your sender reputation, and in the worst cases, your domain being flagged as a source of phishing. For businesses that rely on email marketing or transactional email communications, these are serious consequences that are entirely avoidable with the right setup.

Getting Your Records Set Up Correctly

The good news is that implementing SPF, DKIM and DMARC does not require you to be a developer or a systems administrator. Most domain registrars and DNS providers have straightforward interfaces for adding TXT records. Your email service provider will typically supply you with the exact values you need to enter. The important things to be mindful of are ensuring your SPF record includes all the services you use to send email, that DKIM is enabled within each of those platforms, and that your DMARC policy starts at none while you review reports before moving towards quarantine and ultimately reject.

It is also worth auditing your setup periodically. Businesses add new tools and integrations over time, and if a new sending service is not added to your SPF record, its emails may fail authentication without you realising. Regular checks using a tool like MXToolbox or your DMARC reporting platform will keep you informed and ahead of any potential issues.

The Bottom Line

Understanding what SPF, DKIM and DMARC are and why your emails need them is not just a technical exercise. It is a fundamental part of running a credible, effective and trustworthy email programme. These protocols protect your customers from fraudulent emails, protect your domain reputation from being exploited, and ensure your legitimate messages actually reach the people you are sending them to. If you have not yet verified that all three are correctly configured on your domain, it is one of the most worthwhile tasks you can prioritise today.

I

Ian

Ian has worked in Digital Marketing for decades, and is a Google Partner for Google Ads and an expert in onsite and technical SEO. He has worked with hundreds of clients, helping them achieve success online, through SEO, PPC and Digital Marketing, working with local businesses through to national retailers.

View all posts →

Related Articles