Business Email

How to Configure SPF, DKIM, and DMARC for Your Business Email

Learn how to set up SPF, DKIM, and DMARC on your business email domain to stop spoofing and keep your messages out of spam folders.

Person using a laptop to read an email indoors beside a potted plant.

SPF, DKIM, and DMARC are three DNS records that tell mail servers worldwide that you are the legitimate sender of emails from your domain. Without them, your messages land in spam — or worse, anyone can impersonate you by sending fraudulent emails from your domain name.

This guide explains what each record does, how to create it step by step, and how to verify everything is working correctly.

What Are SPF, DKIM, and DMARC — and Why Do You Need Them?

The three standards work in layers to authenticate your business email:

  • SPF (Sender Policy Framework): lists which mail servers are authorized to send email on behalf of your domain.
  • DKIM (DomainKeys Identified Mail): adds a cryptographic signature to every message, proving it wasn't tampered with in transit.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): instructs receiving servers on what to do when a message fails SPF or DKIM — and sends you reports so you can monitor your domain's email activity.

Without these records, Gmail, Outlook, and other providers flag your emails as suspicious. Since February 2024, Google and Yahoo require SPF and DKIM for senders exceeding 5,000 messages per day.

How to Set Up the SPF Record

SPF is published as a TXT record in your domain's DNS.

Basic format

v=spf1 include:your-provider.com ~all

Replace include:your-provider.com with the value your hosting or mail provider specifies. Common examples:

Provider Include value
cPanel / Exim Your server's outbound hostname
Google Workspace include:_spf.google.com
Microsoft 365 include:spf.protection.outlook.com
Zoho Mail include:zoho.com

Choosing ~all vs -all

  • ~all (softfail): accepts messages but marks them. Recommended when starting out.
  • -all (hardfail): rejects anything not on the authorized list. Use this once you're confident in your setup.

There can only be one SPF record per domain. If you already have one, add new include statements to the existing record rather than creating a second one.

How to Set Up the DKIM Record

DKIM requires a cryptographic key pair: the private key (stored on your mail server) and the public key (published in DNS).

From cPanel

  1. Log in to cPanel → Email → Email Deliverability.
  2. Check the DKIM status next to your domain. If it shows "Problems found," click Repair.
  3. cPanel generates the key pair and automatically publishes the TXT DNS record under the default._domainkey selector.

With Google Workspace or Microsoft 365

Both platforms generate their own key pairs from within their admin consoles (Admin Console → Gmail → Authenticate Email for Google; Microsoft 365 Admin Center → Exchange → DKIM for Microsoft). Copy the TXT record they provide and add it to your domain DNS.

Verifying DKIM

Send a test email to [email protected] and you'll receive an automatic report showing whether DKIM passes or fails.

How to Set Up the DMARC Record

DMARC is published as a TXT record at _dmarc.yourdomain.com.

Minimal policy to start with

v=DMARC1; p=none; rua=mailto:[email protected]
  • p=none: monitor only — no messages are blocked. Ideal for the first weeks.
  • rua: the address where you'll receive daily aggregate reports.

Recommended progression

  1. Weeks 1–2: p=none — review the reports.
  2. Weeks 3–4: p=quarantine; pct=25 — quarantine 25% of failing messages.
  3. Month 2+: p=reject — reject all messages that fail authentication.

Reports arrive in XML format. Free tools like DMARC Analyzer or MxToolbox translate them into readable summaries within seconds.

Verifying Everything Works

After publishing all three records (allow 10–30 minutes for DNS propagation), verify with these tools:

  • MxToolbox.com → SPF Lookup, DKIM Lookup, and DMARC Lookup.
  • Mail-tester.com → send a test message and get a deliverability score out of 10.
  • Google Postmaster Tools → ongoing monitoring for messages sent to Gmail addresses.

If you need help reviewing your hosting's DNS configuration or want a fully managed business email setup, elenlace.com offers expert support every step of the way.

You can also find more guides on authentication and email best practices in our business email section.

Key Takeaways

  • SPF, DKIM, and DMARC work together to authenticate your email and protect your domain from spoofing.
  • SPF defines authorized sending servers; DKIM signs each message; DMARC enforces what happens when they fail.
  • Start with p=none in DMARC, analyze the reports, then move gradually toward p=reject.
  • Only one SPF record is allowed per domain — combine all include statements into a single TXT record.
  • Always verify with MxToolbox and mail-tester.com before assuming your setup is complete.

Set up all three records today and stop losing emails to the spam folder. If you'd rather have an expert handle the setup, the team at elenlace.com can take care of the full configuration for you.

FAQ

What happens if I don't configure SPF, DKIM, and DMARC?

Your emails are far more likely to land in spam, and anyone can impersonate your domain to send fraudulent messages to your clients or suppliers without your knowledge.

Can I have more than one SPF record for my domain?

No. The standard allows only one SPF record per domain. If you need to authorize multiple providers, add all their include statements inside a single TXT record.

How long does DNS propagation take?

Usually between 10 minutes and 48 hours, although most hosting providers update DNS within 30 minutes. Use MxToolbox to check propagation status in real time.

Does DMARC replace SPF or DKIM?

No. DMARC depends on SPF and/or DKIM to function — it evaluates the results of those checks and applies the policy you've defined. All three records are necessary for complete protection.

Useful resources

Other providers and guides worth comparing:

← All