Domain insights

SPF, DKIM and DMARC: a practical email authentication rollout

Inventory every sender, publish one valid SPF policy, sign with DKIM, monitor DMARC alignment, and enforce only after legitimate mail passes.

Email Security
SPF, DKIM and DMARC: a practical email authentication rollout

SPF authorizes sending infrastructure, DKIM adds a verifiable signature, and DMARC requires the visible From domain to align with a passing SPF or DKIM identity. Deploy all three: inventory every service that sends mail, publish one SPF record, enable 2048-bit DKIM when supported, start DMARC with reporting, and move toward quarantine or reject only after legitimate traffic aligns.

What each control does

ControlChecksDoes not prove
SPFWhether the connecting server is authorized for the envelope sender domainThat the visible From domain matches
DKIMWhether a signed message remained intact and the signing domain owns the keyThat every unsigned message is fraudulent
DMARCWhether aligned SPF or DKIM passes for the visible From domainThat message content is safe or wanted
Cartoon email journey through SPF authorization, DKIM signature checking and the DMARC decision
SPF checks the sending path, DKIM checks the signature, and DMARC evaluates alignment with the visible From domain.

Step 1: inventory every sender

List mailbox platforms, help desks, invoicing systems, marketing tools, website forms, monitoring services and any server that sends as your domain. Record its envelope sender, DKIM signing domain and responsible owner. An unknown legitimate sender is the usual reason a team stops at DMARC p=none or accidentally rejects its own mail.

Step 2: publish one SPF record and respect the lookup limit

A domain name must not publish multiple SPF records. Combine authorized senders into one TXT value beginning with v=spf1. RFC 7208 limits mechanisms and modifiers that trigger DNS queries to ten during evaluation; exceeding that limit produces permerror. Includes can expand into more includes, so count the complete chain rather than only the visible terms.

Step 3: enable DKIM with planned selectors

A DKIM selector lets one domain publish multiple public keys, such as selector1._domainkey.example.hn. Give each sending platform its own selector so keys can rotate independently. Gmail requires at least 1024-bit DKIM for messages to personal Gmail accounts and recommends 2048 bits when the provider supports it; prefer 2048 bits unless DNS or platform constraints prevent it.

Step 4: understand DMARC alignment

Visible FromAuthentication resultDMARC outcome
[email protected]SPF passes for bounce.example.hnAligned in relaxed mode because both share example.hn
[email protected]DKIM passes with d=example.hnAligned and passes
[email protected]SPF passes for vendor.example and DKIM uses vendor.exampleNot aligned, so DMARC fails
[email protected]SPF fails but aligned DKIM passesDMARC passes because one aligned method is enough

Step 5: move from monitoring to enforcement

  1. Start with p=none: Publish rua to an address or service prepared to process aggregate XML reports. Observe every legitimate source and alignment result.
  2. Fix before enforcement: Correct missing DKIM, SPF authorization, forwarding behavior and subdomain policy. Do not assume a report source is malicious only because it is unfamiliar.
  3. Test quarantine: Apply quarantine to a controlled percentage if your receiving ecosystem supports gradual rollout, then watch support and report data.
  4. Reach p=reject: Reject only after required senders align and owners accept the policy. Continue monitoring after enforcement.
Illustrated DMARC rollout from monitoring to quarantine and reject enforcement
The sequence matters more than a fixed calendar: monitor, correct legitimate traffic, test enforcement, and only then reject.

The rua address is operational data, not decoration

The rua tag requests aggregate DMARC reports. Those reports summarize authentication and alignment by source, helping you find forgotten services and abuse. Use a dedicated protected mailbox or reporting platform because report volume can be high and XML requires processing; also authorize external report destinations when the DMARC specification requires it.

Domains that never send mail need an explicit policy

For a domain that should neither send nor receive email, publish Null MX using MX 0 . to state that it accepts no mail, an SPF policy such as v=spf1 -all, and a DMARC reject policy after confirming there are no legitimate senders. Apply a similar deliberate policy to unused subdomains rather than leaving them available for impersonation.

Verify DNS and a real message

  1. SPF: Run dig TXT example.hn and confirm there is one v=spf1 policy with all intended senders.
  2. DKIM: Run dig TXT selector1._domainkey.example.hn and compare the published key with the sending service.
  3. DMARC: Run dig TXT _dmarc.example.hn and verify p, rua, alignment mode and subdomain policy.
  4. Message result: Send a controlled message and inspect Authentication-Results for spf=pass, dkim=pass and dmarc=pass plus the domains used for alignment.

Current mailbox-provider expectations

Google and Yahoo require stronger authentication for bulk senders, including SPF, DKIM and DMARC, aligned mail, low complaint rates and easy unsubscribe for applicable subscribed messages. Requirements change, so review the current official sender guidelines before a campaign. Authentication improves identity assurance, but consent, list quality, reputation, TLS and correct message formatting remain essential.

Use a market domain without fragmenting email control

A country domain can make a local brand and sender address easier to recognize, but every sending domain needs its own inventory and authentication. Decide whether the ccTLD will send mail, redirect to a global site or remain defensive. Then confirm registration eligibility, local-presence rules and renewal cost before building SPF, DKIM and DMARC on it.

Frequently asked questions

Can I publish more than one SPF record?

No. Multiple SPF records for the same name cause a permanent error. Merge authorized services into one policy and count all lookup-producing mechanisms across nested includes.

Does DMARC pass when either SPF or DKIM passes?

Only when the passing method also aligns with the visible From domain. A vendor can pass SPF and DKIM for its own domain while your message still fails DMARC alignment.

Should I publish p=reject immediately?

Usually not. Begin with reporting, identify legitimate senders, fix alignment and test quarantine before reject. An immediate reject policy can block invoices, support mail or marketing that was never inventoried.

Do SPF, DKIM and DMARC guarantee inbox placement?

No. They authenticate identity and policy, but providers also evaluate reputation, complaints, consent, content, infrastructure and sending behavior. Treat authentication as a baseline, not a delivery guarantee.