SPF, DKIM & DMARC Tips

25 articles on the everyday administration of SPF, DKIM and DMARC. Reading records, rolling out policy, working through reports, and the mistakes that break mail without anyone noticing. Written to be read in order, but each one stands alone.

Start hereFundamentals 2 min read

Email authentication in plain English

SPF, DKIM and DMARC are three DNS records answering one question for a receiving server: should this message, claiming to be from your domain, be trusted?

Start reading
SPF

What SPF actually does

SPF authorises servers, not messages, and it checks the envelope sender rather than the From address your recipient sees. That explains most SPF confusion.

5 min read
SPF

Reading an SPF record, mechanism by mechanism

A walk through every mechanism and modifier you are likely to meet in a real SPF record.

2 min read
SPF

The SPF ten-lookup limit, and how to stay under it

SPF evaluation is capped at ten DNS lookups. Exceed it and the result is permerror, which most receivers treat as a failure, including DMARC.

4 min read
SPF

-all or ~all: choosing your SPF policy

Hardfail rejects unlisted senders outright; softfail marks them and delivers anyway. Which you want depends on how complete your record already is.

2 min read
SPF

Seven SPF mistakes that break mail quietly

Most broken SPF records look fine at a glance. These are the failure modes that pass visual inspection and still cost you delivery.

2 min read
SPF

Adding a new sender to SPF safely

A short routine for onboarding a new mail vendor: check the lookup budget first, publish second, verify third.

2 min read
SPF

Why SPF fails on forwarded mail

Forwarding rewrites the path but not the sender, so SPF sees the wrong IP. Understanding this stops you chasing a bug that is working as designed.

2 min read
DKIM

What DKIM actually does

DKIM signs the message itself, so the proof travels with the mail. That is why it survives forwarding when SPF does not.

5 min read
DKIM

Selectors: how one domain holds many DKIM keys

The selector is the label that lets each sending service have its own key under the same domain, and it is what makes rotation possible without downtime.

1 min read
DKIM

Publishing your first DKIM key

Generate a 2048-bit key, publish the public half as a TXT record, enable signing, and verify with a real message before you trust it.

2 min read
DKIM

Rotating DKIM keys without dropping mail

Rotation is a four-step overlap: publish the new key, switch signing, wait out mail in flight, then revoke the old one.

5 min read
DKIM

Why a valid DKIM signature can still fail

DMARC only counts a DKIM pass when the signing domain in d= matches the From domain. Vendors that sign with their own domain pass DKIM and fail DMARC.

2 min read
DKIM

Why DKIM signatures break in transit

Anything that modifies signed headers or the body invalidates the signature. Mailing lists are the usual culprit, and there is no way to sign around them.

2 min read
DMARC

What DMARC actually does

DMARC binds SPF and DKIM to the From address your recipients see, tells receivers what to do on failure, and sends you reports about it.

5 min read
DMARC

Every DMARC tag, and which ones matter

A DMARC record has eleven possible tags. Four of them do the work; the rest are tuning you will rarely touch.

2 min read
DMARC

Publishing your first DMARC record

Start at p=none with a reporting address. It changes nothing about delivery and gives you the data you need for every decision that follows.

2 min read
DMARC

Alignment, the idea that makes DMARC work

Alignment requires the domain SPF or DKIM authenticated to be the domain your recipient sees. Without it, authentication proves nothing useful.

5 min read
DMARC

Reading a DMARC aggregate report

The XML is dense but the structure is simple: who sent, from where, how much, and what the checks said. Here is how to turn it into a decision.

5 min read
DMARC

Moving from p=none to p=reject safely

Enforcement is a staged rollout driven by reports, not a flag you flip. Here is the sequence, and the signals that say you are ready for the next step.

5 min read
DMARC

Subdomains, sp= and the domains you forgot

A DMARC record on the parent domain covers every subdomain by default. That is usually what you want, and occasionally exactly what breaks things.

1 min read
DMARC

DMARC failure reports and the ruf= tag

Forensic reports carry real message data, one per failure. Few receivers send them and the privacy cost is real, but they answer what aggregates cannot.

1 min read
Fundamentals

DNS hygiene for email administrators

TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.

2 min read
Fundamentals

Locking down domains that never send mail

Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.

2 min read
Fundamentals

A monthly email authentication checklist

Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.

2 min read