What SPF, DKIM and DMARC do
Email was designed without sender authentication, so anyone can put your domain in the From line. Three DNS records fix that together:
- SPF (a TXT record starting
v=spf1on the domain) lists the servers allowed to send mail for it. Receivers check the connecting IP against the list. - DKIM signs each message with a private key; receivers fetch the public key from
selector._domainkey.domainand verify that the message was not changed. - DMARC (a TXT record on
_dmarc.domain) says what to do when a message fails both SPF and DKIM alignment with the From domain (p=none,quarantineorreject) and where to send reports (rua=).
How to read the results
- Each check is marked ✓ (fine), ! (works but should be improved) or ✗ (broken or unsafe).
- The SPF lookup meter counts every
include,a,mx,ptr,existsandredirect, through all nested includes. Over 10, SPF fails for every message. - The term by term view expands each
include:into the provider's own record, so you can see where your lookups go. - The DMARC table explains each tag. The policy badge shows how protected the domain is:
rejectis the goal.
Common mistakes
- Two SPF records. Adding a second
v=spf1record for a new provider breaks SPF for all mail. Merge them:v=spf1 include:_spf.google.com include:sendgrid.net ~all. - Too many includes. Each email provider's include can cost several lookups. Remove providers you no longer use before flattening.
+allor a bareall. It allows every server on the internet; end with~allor-all.- Staying on
p=noneforever. It only monitors. Read the reports for a few weeks, fix legitimate senders, then move toquarantineandreject. - No
rua. Without reports you cannot see which services send as your domain, so you can never safely enforce. - Forgetting domains that send no mail. Parked domains should publish
v=spf1 -allandv=DMARC1; p=rejectso they cannot be spoofed.
FAQ
What is the SPF 10 DNS lookup limit?
RFC 7208 caps an SPF check at 10 mechanisms that need DNS queries: include, a, mx, ptr, exists and redirect, counted across all nested includes. ip4, ip6 and all are free. Going over makes SPF fail with a permerror, which can break your mail authentication silently.
Should I use ~all or -all?
Both are fine once DMARC is enforcing, because DMARC decides what happens to failing mail. ~all (softfail) is the common, safer choice while you are still finding all your senders. Never use +all: it authorises the whole internet.
Is p=none bad?
p=none is monitoring only: spoofed mail still gets delivered. It is the right first step so you can read the rua reports and fix legitimate senders, but the goal is p=quarantine and then p=reject.
How do I find my DKIM selector?
Open a message you sent, view the original headers and find the DKIM-Signature header. The s= value is the selector and d= is the domain. Google Workspace uses google by default; Microsoft 365 uses selector1 and selector2.
How does the checker look up DNS?
It sends TXT queries to Cloudflare's public DNS-over-HTTPS resolver (1.1.1.1), so you see what the public internet sees. Results can lag behind a change you just made by the record's TTL.