SPF, DKIM & DMARC Setup: A Practical Guide for Business Email

SPF authorises sending servers, DKIM signs messages, and DMARC checks how authenticated domains align with the visible From address. Set up the records for your actual sending services, then verify real messages before tightening your policy.

QUICK ANSWER

SPF authorises which servers may send for your domain, DKIM cryptographically signs each message, and DMARC checks whether SPF or DKIM aligns with the visible From address and tells receivers what to do on failure. Inventory every sending service first, configure SPF and DKIM per provider, publish DMARC in monitoring mode (p=none), verify real messages, then move toward enforcement only once every legitimate sender passes.

Start With a Sender Inventory

List every system that sends using your domain: employee mailboxes, your website, CRM, campaign platform, support desk and transactional email provider. Record the visible From domain and the authentication settings issued by each provider.

Find the DNS host that controls the domain's authoritative records. It may be different from your website host or registrar. Export the current records before changing them, and keep an owner for each sending service so later migrations can be checked.

Examples are not production credentials. Replace example.com and reporting addresses with domains and inboxes you control. Use the exact DKIM and sending records issued by your own provider.
MethodMain QuestionTypical DNS Location
SPFIs this server authorised for the envelope-sender domain?A TXT record on that domain
DKIMCan the message's domain signature be verified?A provider-issued selector under _domainkey
DMARCDoes SPF or DKIM pass with alignment to the visible From domain?A TXT record at _dmarc

Step 1: Configure SPF for Your Senders

Review the existing SPF policy before adding a provider. Keep one SPF policy record at a given domain name and include the legitimate sending sources required there. Do not replace a working policy with a sample that leaves out your CRM or campaign service.

Google Workspace-only example: Google's setup guide provides the following policy when Google Workspace is the only sending service:

Type: TXT Name: @ Value: v=spf1 include:_spf.google.com ~all

Additional providers change the required policy. The return-path domain used by an email platform can also differ from your visible From domain, so follow that platform's authentication instructions. Keep DNS lookup limits in mind when combining providers.

Reference: Google Workspace SPF setup.

Step 2: Publish and Activate DKIM

  1. Open domain authentication in the service that sends your email.
  2. Generate or obtain the provider's DKIM selector and DNS record.
  3. Add the exact TXT or CNAME record that the provider requests.
  4. Verify DNS, then activate signing in the provider if it requires a separate activation step.
  5. Send a test message from that service and inspect its DKIM result.

In Google Workspace, this is under the Gmail authentication settings in the Admin console. Its guide recommends a 2048-bit key when your DNS provider supports it. Other email platforms may supply CNAME records instead of a TXT public key.

Illustrative record location, not a usable key: selector._domainkey.example.com Copy the selector and value from your sending provider.

Different senders can use different selectors on the same domain. Reference: Google Workspace DKIM setup.

Step 3: Introduce DMARC With Monitoring

After configuring SPF and DKIM, publish a DMARC record for the visible From domain. A monitoring policy lets you inspect reports before moving to enforcement.

Illustrative monitoring record: Type: TXT Name: _dmarc Value: v=DMARC1; p=none; rua=mailto:dmarc@example.com

Replace the example reporting address with a monitored destination you control. An external reporting service may require additional authorisation records. A p=none policy requests reporting without requesting quarantine or rejection on the basis of DMARC failure.

Review all legitimate sending streams before gradually adopting a stricter policy. Do not change an existing enforced policy to monitoring without understanding why it was configured that way. Reference: Google Workspace DMARC setup.

Step 4: Check Alignment on Real Messages

A generic SPF pass is not enough to establish DMARC success. At least one passing method must align with the visible From domain: the SPF envelope-sender domain or the DKIM signing domain. The policy's alignment mode determines the permitted match.

Send tests from each platform in your inventory. Inspect the receiving provider's authentication results, including the visible From, return-path and DKIM signing domain. A mailbox message passing does not prove that your website's password-reset messages use the same configuration.

DMARC authentication does not guarantee inbox placement. It establishes domain authentication and policy signals; receiver filtering still evaluates other factors. Technical reference: DMARC specification, RFC 7489.

Check the Receiving Provider's Sending Requirements

Google's personal Gmail sender rules distinguish all senders from bulk senders. Bulk-sender requirements include SPF, DKIM, DMARC and domain alignment. Marketing and subscribed messages covered by those requirements must support one-click unsubscribe and a visible unsubscribe link. Requirements also address transport security, DNS and spam complaints.

Check the current Gmail sender guidelines against your sending volume and message type. A footer link alone does not implement the one-click unsubscribe headers.

Troubleshoot One Sending Stream at a Time

SymptomWhat to Inspect
Record cannot be foundAuthoritative DNS host, full record name and duplicated domain suffix
SPF errorConflicting policies, missing provider details or excessive DNS lookups
DKIM is absentSigning activation, correct selector and the actual sending service
SPF/DKIM passes but DMARC failsAlignment with the visible From domain
Only website emails failThe website's actual SMTP/API credentials and sender identity
Authentication passes but mail lands in spamRecipient expectations, complaints, list quality and sending pattern

Record the change and test result for each service. Allow for DNS caching and the provider's verification process before repeatedly editing records. If authentication is correct, continue with the spam placement guide.

For an implementation discussion, share your domain and platform names through our SMTP service enquiry. Arrange access through your normal secure process; do not place passwords or private keys in an enquiry message.

Frequently Asked Questions

Only the Google Workspace-only SPF example applies to that specific setup. The DMARC domain and address are examples. DKIM and additional sending values must come from your actual provider.

The passing signature may use a domain that is not aligned with the visible From address. Inspect the signing domain and the applicable DMARC alignment mode.

For a new rollout, first identify and authenticate legitimate senders and review reports. Move toward enforcement when those streams are verified. Review an existing policy before changing it.

No. Authentication is one part of email delivery. Recipient expectations, complaints, reputation and sending practices still matter.

Discuss Email Authentication Setup

Share your domain and sending platforms — we'll help you review SPF, DKIM and DMARC before you tighten enforcement.

Discuss My Setup Call +91-7669990407

Related Email Services & Guides

SMTP Infrastructure → Troubleshoot Spam Placement → Transactional Email Services → Pricing Guide → Workflow Playbook → Service Comparison →

Need Help Getting Authentication Right?

Share your domain and sending platforms — we'll walk through SPF, DKIM and DMARC with you.

Get Started Call: +91-7669990407
Our Happy Clients

Trusted by 500+ Businesses Across India

From startups to enterprises — brands that grow with MetaReach

WhatsApp Facebook Instagram YouTube LinkedIn X / Twitter
☎ Instant Call Back FREE
or request a call back

We'll call you back within 5 minutes