Skip to content
toolsdocks

SPF, DKIM and DMARC in plain English

2 min read · Updated 3 October 2026

Anyone can type any "From" address into an email. Three DNS records let receiving mail servers check whether a message really comes from your domain.

SPF: who may send

A Sender Policy Framework record is a TXT record on your domain listing the servers allowed to send its mail:

v=spf1 include:_spf.example.net ip4:203.0.113.10 ~all

  • include: pulls in another domain's list (typical for email providers).
  • ip4: / ip6: allow specific addresses.
  • The ending says what to do with everything else: -all (fail), ~all (soft fail), ?all (neutral).

Common mistakes: having two SPF records (only one is allowed), and exceeding the 10 DNS-lookup limit: each include, a, mx, exists and redirect costs a lookup, including the ones nested inside included records. Past ten, SPF returns a permanent error and receivers may treat the check as failed.

DKIM: a signature on each message

DomainKeys Identified Mail adds a cryptographic signature to each email. The public key is published at <selector>._domainkey.<your domain>, for example s1._domainkey.example.com. Your email provider tells you the selector and the value to publish. Because selectors are chosen by the provider, a checker can only look up the ones you know or common defaults.

DMARC: the policy that ties them together

DMARC is a TXT record at _dmarc.<your domain>:

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=r

  • p= is the policy for mail that fails: none (monitor only), quarantine (usually spam folder), reject.
  • rua= asks receivers to send aggregate reports.
  • adkim / aspf set strict (s) or relaxed (r) alignment between the From domain and the SPF/DKIM domains.

A message passes DMARC when SPF or DKIM passes and the domain it passed for aligns with the visible From address.

A sensible rollout

  1. Publish SPF and enable DKIM with your provider.
  2. Add DMARC with p=none and a reporting address; read the reports for a few weeks.
  3. Move to p=quarantine, then p=reject once legitimate mail always passes.

Checking your records

The SPF, DKIM and DMARC checker looks up your records from your browser using public DNS-over-HTTPS resolvers, counts SPF lookups and explains each tag. The DNS lookup tool shows the raw records. Valid records help deliverability but do not guarantee it: mailbox providers also weigh reputation and content.