Guides

How email authentication works: SPF, DKIM and DMARC together

SPF, DKIM and DMARC are three separate DNS records that only protect your domain when they work together. This is the order that makes sense, and the reasons mail fails even when all three exist.

Last reviewed: 2026-09-30

The problem they solve

Email lets any sender write any address in the From: line. Without authentication, a receiver cannot tell a real invoice from your domain from a forged one. The three standards give receivers evidence and tell them what to do when the evidence is missing.

What each record does

  • SPF (TXT at your domain): which servers may send mail for the envelope sender (Return-Path) domain.
  • DKIM (TXT at selector._domainkey): a public key; each message carries a signature made with the matching private key, so the content can be verified as unchanged and signed by your domain.
  • DMARC (TXT at _dmarc): requires that SPF or DKIM passes for a domain that matches the visible From: domain (alignment), tells receivers what to do otherwise (none, quarantine, reject), and where to send reports.

Why alignment is the key idea

SPF and DKIM on their own authenticate some domain — not necessarily yours. A phishing mail can pass SPF for the attacker's own domain while showing your name in From:. DMARC closes that gap: at least one of SPF or DKIM must pass for the same domain the recipient sees.

Why authentication fails for legitimate mail

  • Forwarding: the forwarder's server is not in your SPF record. DKIM usually survives forwarding, so sign everything with DKIM.
  • Third-party senders (newsletters, CRM, ticketing): they send from their servers and often sign with their own domain. Add them to SPF and set up DKIM with your domain on their platform.
  • Mailing lists that change the subject or footer: they break the DKIM signature. ARC helps some receivers here.
  • Too many SPF includes: more than 10 DNS lookups makes SPF return an error (permerror).

A safe order to set things up

  1. Inventory every service that sends mail as your domain.
  2. Publish or correct SPF so it lists exactly those services and ends in ~all or -all.
  3. Enable DKIM signing on every sending platform.
  4. Publish DMARC with p=none and a rua= report address; read the reports for 2–4 weeks.
  5. Once legitimate mail passes, move to p=quarantine, then p=reject.
example.com.         TXT "v=spf1 include:_spf.google.com -all"
s1._domainkey        TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
_dmarc.example.com.  TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

How to verify

Scan the domain with Korantix Email Security to see all three records, the SPF lookup count and the DMARC policy. Then send a real message to a mailbox you control and read its Authentication-Results header: it shows spf=, dkim= and dmarc= as the receiver saw them.

Check this on your domain →