SPF, DKIM, and DMARC are three DNS records that tell mail servers worldwide that you are the legitimate sender of emails from your domain. Without them, your messages land in spam — or worse, anyone can impersonate you by sending fraudulent emails from your domain name.
This guide explains what each record does, how to create it step by step, and how to verify everything is working correctly.
What Are SPF, DKIM, and DMARC — and Why Do You Need Them?
The three standards work in layers to authenticate your business email:
- SPF (Sender Policy Framework): lists which mail servers are authorized to send email on behalf of your domain.
- DKIM (DomainKeys Identified Mail): adds a cryptographic signature to every message, proving it wasn't tampered with in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance): instructs receiving servers on what to do when a message fails SPF or DKIM — and sends you reports so you can monitor your domain's email activity.
Without these records, Gmail, Outlook, and other providers flag your emails as suspicious. Since February 2024, Google and Yahoo require SPF and DKIM for senders exceeding 5,000 messages per day.
How to Set Up the SPF Record
SPF is published as a TXT record in your domain's DNS.
Basic format
v=spf1 include:your-provider.com ~all
Replace include:your-provider.com with the value your hosting or mail provider specifies. Common examples:
| Provider | Include value |
|---|---|
| cPanel / Exim | Your server's outbound hostname |
| Google Workspace | include:_spf.google.com |
| Microsoft 365 | include:spf.protection.outlook.com |
| Zoho Mail | include:zoho.com |
Choosing ~all vs -all
~all(softfail): accepts messages but marks them. Recommended when starting out.-all(hardfail): rejects anything not on the authorized list. Use this once you're confident in your setup.
There can only be one SPF record per domain. If you already have one, add new include statements to the existing record rather than creating a second one.
How to Set Up the DKIM Record
DKIM requires a cryptographic key pair: the private key (stored on your mail server) and the public key (published in DNS).
From cPanel
- Log in to cPanel → Email → Email Deliverability.
- Check the DKIM status next to your domain. If it shows "Problems found," click Repair.
- cPanel generates the key pair and automatically publishes the
TXTDNS record under thedefault._domainkeyselector.
With Google Workspace or Microsoft 365
Both platforms generate their own key pairs from within their admin consoles (Admin Console → Gmail → Authenticate Email for Google; Microsoft 365 Admin Center → Exchange → DKIM for Microsoft). Copy the TXT record they provide and add it to your domain DNS.
Verifying DKIM
Send a test email to [email protected] and you'll receive an automatic report showing whether DKIM passes or fails.
How to Set Up the DMARC Record
DMARC is published as a TXT record at _dmarc.yourdomain.com.
Minimal policy to start with
v=DMARC1; p=none; rua=mailto:[email protected]
p=none: monitor only — no messages are blocked. Ideal for the first weeks.rua: the address where you'll receive daily aggregate reports.
Recommended progression
- Weeks 1–2:
p=none— review the reports. - Weeks 3–4:
p=quarantine; pct=25— quarantine 25% of failing messages. - Month 2+:
p=reject— reject all messages that fail authentication.
Reports arrive in XML format. Free tools like DMARC Analyzer or MxToolbox translate them into readable summaries within seconds.
Verifying Everything Works
After publishing all three records (allow 10–30 minutes for DNS propagation), verify with these tools:
- MxToolbox.com → SPF Lookup, DKIM Lookup, and DMARC Lookup.
- Mail-tester.com → send a test message and get a deliverability score out of 10.
- Google Postmaster Tools → ongoing monitoring for messages sent to Gmail addresses.
If you need help reviewing your hosting's DNS configuration or want a fully managed business email setup, elenlace.com offers expert support every step of the way.
You can also find more guides on authentication and email best practices in our business email section.
Key Takeaways
- SPF, DKIM, and DMARC work together to authenticate your email and protect your domain from spoofing.
- SPF defines authorized sending servers; DKIM signs each message; DMARC enforces what happens when they fail.
- Start with
p=nonein DMARC, analyze the reports, then move gradually towardp=reject. - Only one SPF record is allowed per domain — combine all
includestatements into a single TXT record. - Always verify with MxToolbox and mail-tester.com before assuming your setup is complete.
Set up all three records today and stop losing emails to the spam folder. If you'd rather have an expert handle the setup, the team at elenlace.com can take care of the full configuration for you.
FAQ
What happens if I don't configure SPF, DKIM, and DMARC?
Your emails are far more likely to land in spam, and anyone can impersonate your domain to send fraudulent messages to your clients or suppliers without your knowledge.
Can I have more than one SPF record for my domain?
No. The standard allows only one SPF record per domain. If you need to authorize multiple providers, add all their include statements inside a single TXT record.
How long does DNS propagation take?
Usually between 10 minutes and 48 hours, although most hosting providers update DNS within 30 minutes. Use MxToolbox to check propagation status in real time.
Does DMARC replace SPF or DKIM?
No. DMARC depends on SPF and/or DKIM to function — it evaluates the results of those checks and applies the policy you've defined. All three records are necessary for complete protection.
Useful resources
Other providers and guides worth comparing: