SPF, DKIM and DMARC

Three records decide whether your invoices reach the inbox. Most of the advice about them online is old, and two of the most common "fixes" make things worse.

SPF

A TXT record listing who may send as your domain. Ours is included when you add the domain.

Two mistakes, both common. One: publishing two SPF records. That is not twice the protection, it is an error, and strict receivers fail both. Merge them into one v=spf1. Two: going over ten DNS lookups — every include: costs one, and past ten the record is invalid. If you have collected five marketing tools over the years, you are probably over.

DKIM

A cryptographic signature on every outgoing message. The receiver checks it against a public key in your DNS and knows the message was not altered in transit. We hold the private key and publish the record for you, so there is nothing to rotate by hand and nothing to paste wrong.

DMARC

Tells receivers what to do when the first two fail, and where to send reports. Start with p=none, which changes nothing and only collects reports. Move to quarantine, then reject, once the reports show your legitimate senders all passing.

Do not publish p=reject on day one. If you have a newsletter tool, a CRM or an accounting package that sends as your domain and you have not listed it, that mail starts being rejected immediately — by everyone, at once.

Forwarding breaks SPF, and that is normal

When someone forwards your message, the forwarding server is not in your SPF record, so SPF fails. DKIM usually survives, and DMARC passes if either one aligns. This is the main reason DKIM matters and SPF alone is not enough.

Still landing in spam?

Check, in this order: that the three records are correct and the domain is verified; that you are sending from your own domain rather than ours; that your sending volume has not jumped suddenly from zero; and that the content is not doing something obvious, like one big image and no text. Reputation is built over weeks, and a brand-new domain that sends two thousand messages on its first day will be treated accordingly.

Questions people actually ask

Can I have two SPF records?

No. Two is a configuration error — merge them into one v=spf1 record. Strict receivers fail a domain with two.

Should I set DMARC to reject straight away?

No. Start at p=none, read the reports for a few weeks until every legitimate sender passes, then tighten. Going straight to reject breaks anything you forgot about, instantly.

Why does my mail fail SPF when it is forwarded?

Because the forwarding server is not in your SPF record. That is expected. DKIM survives forwarding, which is why DMARC accepts either one passing.

Next

← All guides