SPF authorises sending servers, DKIM signs messages, and DMARC checks how authenticated domains align with the visible From address. Set up the records for your actual sending services, then verify real messages before tightening your policy.
SPF authorises which servers may send for your domain, DKIM cryptographically signs each
message, and DMARC checks whether SPF or DKIM aligns with the visible From address and tells
receivers what to do on failure. Inventory every sending service first, configure SPF and DKIM
per provider, publish DMARC in monitoring mode (p=none), verify real messages, then
move toward enforcement only once every legitimate sender passes.
List every system that sends using your domain: employee mailboxes, your website, CRM, campaign platform, support desk and transactional email provider. Record the visible From domain and the authentication settings issued by each provider.
Find the DNS host that controls the domain's authoritative records. It may be different from your website host or registrar. Export the current records before changing them, and keep an owner for each sending service so later migrations can be checked.
| Method | Main Question | Typical DNS Location |
|---|---|---|
| SPF | Is this server authorised for the envelope-sender domain? | A TXT record on that domain |
| DKIM | Can the message's domain signature be verified? | A provider-issued selector under _domainkey |
| DMARC | Does SPF or DKIM pass with alignment to the visible From domain? | A TXT record at _dmarc |
Review the existing SPF policy before adding a provider. Keep one SPF policy record at a given domain name and include the legitimate sending sources required there. Do not replace a working policy with a sample that leaves out your CRM or campaign service.
Google Workspace-only example: Google's setup guide provides the following policy when Google Workspace is the only sending service:
Additional providers change the required policy. The return-path domain used by an email platform can also differ from your visible From domain, so follow that platform's authentication instructions. Keep DNS lookup limits in mind when combining providers.
Reference: Google Workspace SPF setup.
In Google Workspace, this is under the Gmail authentication settings in the Admin console. Its guide recommends a 2048-bit key when your DNS provider supports it. Other email platforms may supply CNAME records instead of a TXT public key.
Different senders can use different selectors on the same domain. Reference: Google Workspace DKIM setup.
After configuring SPF and DKIM, publish a DMARC record for the visible From domain. A monitoring policy lets you inspect reports before moving to enforcement.
Replace the example reporting address with a monitored
destination you control. An external reporting service may require additional authorisation
records. A p=none policy requests reporting without requesting quarantine or
rejection on the basis of DMARC failure.
Review all legitimate sending streams before gradually adopting a stricter policy. Do not change an existing enforced policy to monitoring without understanding why it was configured that way. Reference: Google Workspace DMARC setup.
A generic SPF pass is not enough to establish DMARC success. At least one passing method must align with the visible From domain: the SPF envelope-sender domain or the DKIM signing domain. The policy's alignment mode determines the permitted match.
Send tests from each platform in your inventory. Inspect the receiving provider's authentication results, including the visible From, return-path and DKIM signing domain. A mailbox message passing does not prove that your website's password-reset messages use the same configuration.
DMARC authentication does not guarantee inbox placement. It establishes domain authentication and policy signals; receiver filtering still evaluates other factors. Technical reference: DMARC specification, RFC 7489.
Google's personal Gmail sender rules distinguish all senders from bulk senders. Bulk-sender requirements include SPF, DKIM, DMARC and domain alignment. Marketing and subscribed messages covered by those requirements must support one-click unsubscribe and a visible unsubscribe link. Requirements also address transport security, DNS and spam complaints.
Check the current Gmail sender guidelines against your sending volume and message type. A footer link alone does not implement the one-click unsubscribe headers.
| Symptom | What to Inspect |
|---|---|
| Record cannot be found | Authoritative DNS host, full record name and duplicated domain suffix |
| SPF error | Conflicting policies, missing provider details or excessive DNS lookups |
| DKIM is absent | Signing activation, correct selector and the actual sending service |
| SPF/DKIM passes but DMARC fails | Alignment with the visible From domain |
| Only website emails fail | The website's actual SMTP/API credentials and sender identity |
| Authentication passes but mail lands in spam | Recipient expectations, complaints, list quality and sending pattern |
Record the change and test result for each service. Allow for DNS caching and the provider's verification process before repeatedly editing records. If authentication is correct, continue with the spam placement guide.
For an implementation discussion, share your domain and platform names through our SMTP service enquiry. Arrange access through your normal secure process; do not place passwords or private keys in an enquiry message.
Only the Google Workspace-only SPF example applies to that specific setup. The DMARC domain and address are examples. DKIM and additional sending values must come from your actual provider.
The passing signature may use a domain that is not aligned with the visible From address. Inspect the signing domain and the applicable DMARC alignment mode.
For a new rollout, first identify and authenticate legitimate senders and review reports. Move toward enforcement when those streams are verified. Review an existing policy before changing it.
No. Authentication is one part of email delivery. Recipient expectations, complaints, reputation and sending practices still matter.
Share your domain and sending platforms — we'll help you review SPF, DKIM and DMARC before you tighten enforcement.
Share your domain and sending platforms — we'll walk through SPF, DKIM and DMARC with you.
Get Started Call: +91-7669990407From startups to enterprises — brands that grow with MetaReach