Email

SPF, DKIM and DMARC: A Practical Setup Guide

Inventory your sending systems and introduce email authentication without blocking legitimate mail.

SPF identifies authorised sending infrastructure, DKIM signs messages, and DMARC checks alignment with the visible From domain and applies a policy. These records work together, but copying generic values can disrupt legitimate business mail.

Practical steps

  1. Inventory every sender: hosted mailboxes, website applications, transactional platforms and newsletter tools. Obtain each provider's current DNS requirements.
  2. Publish a single valid SPF policy for the domain, merging authorised mechanisms carefully and respecting DNS lookup limits. Do not publish several competing SPF records.
  3. Enable DKIM for each sending provider and publish its exact selector record. Protect private signing keys and never place them in DNS.
  4. Introduce DMARC with a monitoring policy appropriate to your rollout, review legitimate senders and alignment, then consider stricter enforcement with a controlled plan. Protect any mailbox receiving reports.

Check the result

Send through each authorised service and inspect SPF, DKIM and DMARC results in recipient headers. Review reports for unexpected senders before moving to an enforcement policy.

Before you proceed

A reject policy can block valid mail when third-party senders are not aligned. Do not paste sample DNS values as production records without checking the domain and provider instructions.