Email Deliverability: SPF, DKIM and DMARC in Plain English
If your emails land in spam, your marketing is wasted. Here is what SPF, DKIM and DMARC do and why Gmail and Yahoo now require them.
You can write a brilliant email, but if it lands in spam, nobody reads it. Major inbox providers now require senders to prove they are legitimate, and three DNS records do most of that work: SPF, DKIM and DMARC.
SPF: who is allowed to send
Sender Policy Framework is a DNS record listing the servers allowed to send email for your domain, for example Google Workspace, Microsoft 365 and your email marketing platform. Emails from unlisted servers look suspicious.
DKIM: proof the email was not altered
DomainKeys Identified Mail adds a digital signature to each message. Receiving servers check the signature against a public key in your DNS to confirm the email genuinely came from your domain and was not changed in transit.
DMARC: what to do when checks fail
DMARC tells inbox providers what to do with emails that fail SPF or DKIM: nothing (p=none), send to spam (p=quarantine) or reject (p=reject). It also sends you reports showing who is sending email using your domain.
Why this matters now
Since 2024, Google and Yahoo have required bulk senders to authenticate with SPF and DKIM, publish a DMARC policy, offer one-click unsubscribe and keep spam complaint rates low. Even smaller senders see better inbox placement when authentication is in place.
A safe rollout plan
- List every service that sends email for your domain (office email, CRM, marketing platform, website forms, invoicing).
- Create one SPF record that includes them all.
- Enable DKIM in each service and add the DNS records it provides.
- Publish DMARC at
p=nonewith a reporting address and review reports for a few weeks. - Move to
p=quarantine, thenp=reject, once all legitimate email passes.
Other deliverability habits
- Only email people who opted in.
- Remove bounced and long-inactive contacts regularly.
- Avoid misleading subject lines.
- Send consistently rather than in sudden large bursts.
Our email team configures authentication as part of every email marketing setup.
Frequently asked questions
Can I have more than one SPF record?
No. A domain should have exactly one SPF record. Combine all sending services into that single record.
Will DMARC block my own emails?
Not if you start with p=none and review reports first. Only tighten the policy once all legitimate sources pass authentication.