SPF, DKIM and DMARC are DNS records that prove emails from your domain are genuine. Major mailbox providers increasingly expect them.
SPF
Lists the servers allowed to send email for your domain. You can only have one SPF record, so every sending service must be included in it.
DKIM
Adds a digital signature to outgoing emails. In Microsoft 365 you enable it in the Defender portal and publish two CNAME records.
DMARC
Tells receiving servers what to do if SPF or DKIM fail, and sends you reports. Start with p=none to monitor, then move to quarantine and reject once all legitimate senders pass.
Common mistakes
- Multiple SPF records
- Forgetting newsletter or CRM platforms
- Jumping straight to reject
We can do this for you through our business email DNS set-up service.
