What SPF, DKIM and DMARC do

Email was designed without sender authentication, so anyone can put your domain in the From line. Three DNS records fix that together:

  • SPF (a TXT record starting v=spf1 on the domain) lists the servers allowed to send mail for it. Receivers check the connecting IP against the list.
  • DKIM signs each message with a private key; receivers fetch the public key from selector._domainkey.domain and verify that the message was not changed.
  • DMARC (a TXT record on _dmarc.domain) says what to do when a message fails both SPF and DKIM alignment with the From domain (p=none, quarantine or reject) and where to send reports (rua=).

How to read the results

  • Each check is marked ✓ (fine), ! (works but should be improved) or ✗ (broken or unsafe).
  • The SPF lookup meter counts every include, a, mx, ptr, exists and redirect, through all nested includes. Over 10, SPF fails for every message.
  • The term by term view expands each include: into the provider's own record, so you can see where your lookups go.
  • The DMARC table explains each tag. The policy badge shows how protected the domain is: reject is the goal.

Common mistakes

  • Two SPF records. Adding a second v=spf1 record for a new provider breaks SPF for all mail. Merge them: v=spf1 include:_spf.google.com include:sendgrid.net ~all.
  • Too many includes. Each email provider's include can cost several lookups. Remove providers you no longer use before flattening.
  • +all or a bare all. It allows every server on the internet; end with ~all or -all.
  • Staying on p=none forever. It only monitors. Read the reports for a few weeks, fix legitimate senders, then move to quarantine and reject.
  • No rua. Without reports you cannot see which services send as your domain, so you can never safely enforce.
  • Forgetting domains that send no mail. Parked domains should publish v=spf1 -all and v=DMARC1; p=reject so they cannot be spoofed.

FAQ

What is the SPF 10 DNS lookup limit?

RFC 7208 caps an SPF check at 10 mechanisms that need DNS queries: include, a, mx, ptr, exists and redirect, counted across all nested includes. ip4, ip6 and all are free. Going over makes SPF fail with a permerror, which can break your mail authentication silently.

Should I use ~all or -all?

Both are fine once DMARC is enforcing, because DMARC decides what happens to failing mail. ~all (softfail) is the common, safer choice while you are still finding all your senders. Never use +all: it authorises the whole internet.

Is p=none bad?

p=none is monitoring only: spoofed mail still gets delivered. It is the right first step so you can read the rua reports and fix legitimate senders, but the goal is p=quarantine and then p=reject.

How do I find my DKIM selector?

Open a message you sent, view the original headers and find the DKIM-Signature header. The s= value is the selector and d= is the domain. Google Workspace uses google by default; Microsoft 365 uses selector1 and selector2.

How does the checker look up DNS?

It sends TXT queries to Cloudflare's public DNS-over-HTTPS resolver (1.1.1.1), so you see what the public internet sees. Results can lag behind a change you just made by the record's TTL.