Setting Up SPF, DKIM & DMARC

Last updated: July 17, 2026

Email authentication proves your messages genuinely come from your domain. Without it, mailbox providers (Gmail, Outlook) are far more likely to junk or reject your mail — and since 2024 both Google and Microsoft require SPF + DKIM + DMARC for bulk senders. Set them up in this order: SPF → DKIM → DMARC.

The three records at a glance

Record

What it does

Where it lives

 

SPF

Lists the servers allowed to send mail for your domain

TXT record on your domain

DKIM

Cryptographically signs your mail so it can't be tampered with or forged

TXT record (published key)

DMARC

Tells receivers what to do with mail that fails SPF/DKIM, and sends you reports

TXT record at _dmarc.yourdomain

Setup order & tips

  1. SPF first, then DKIM — let both authenticate for at least 48 hours before turning on DMARC.

  2. Start DMARC at p=none (monitor only) to collect reports without affecting delivery, then tighten to quarantine and eventually reject once you confirm legit mail passes.

  3. DNS changes can take up to 48 hours to propagate.

  4. Only one SPF record per domain — merge sources, don't add a second.

Google Workspace

Microsoft 365