SPF, DKIM & DMARC Tips
25 articles on the everyday administration of SPF, DKIM and DMARC. Reading records, rolling out policy, working through reports, and the mistakes that break mail without anyone noticing. Written to be read in order, but each one stands alone.
Email authentication in plain English
SPF, DKIM and DMARC are three DNS records answering one question for a receiving server: should this message, claiming to be from your domain, be trusted?
Start readingWhat SPF actually does
SPF authorises servers, not messages, and it checks the envelope sender rather than the From address your recipient sees. That explains most SPF confusion.
5 min readReading an SPF record, mechanism by mechanism
A walk through every mechanism and modifier you are likely to meet in a real SPF record.
2 min readThe SPF ten-lookup limit, and how to stay under it
SPF evaluation is capped at ten DNS lookups. Exceed it and the result is permerror, which most receivers treat as a failure, including DMARC.
4 min read-all or ~all: choosing your SPF policy
Hardfail rejects unlisted senders outright; softfail marks them and delivers anyway. Which you want depends on how complete your record already is.
2 min readSeven SPF mistakes that break mail quietly
Most broken SPF records look fine at a glance. These are the failure modes that pass visual inspection and still cost you delivery.
2 min readAdding a new sender to SPF safely
A short routine for onboarding a new mail vendor: check the lookup budget first, publish second, verify third.
2 min readWhy SPF fails on forwarded mail
Forwarding rewrites the path but not the sender, so SPF sees the wrong IP. Understanding this stops you chasing a bug that is working as designed.
2 min readWhat DKIM actually does
DKIM signs the message itself, so the proof travels with the mail. That is why it survives forwarding when SPF does not.
5 min readSelectors: how one domain holds many DKIM keys
The selector is the label that lets each sending service have its own key under the same domain, and it is what makes rotation possible without downtime.
1 min readPublishing your first DKIM key
Generate a 2048-bit key, publish the public half as a TXT record, enable signing, and verify with a real message before you trust it.
2 min readRotating DKIM keys without dropping mail
Rotation is a four-step overlap: publish the new key, switch signing, wait out mail in flight, then revoke the old one.
5 min readWhy a valid DKIM signature can still fail
DMARC only counts a DKIM pass when the signing domain in d= matches the From domain. Vendors that sign with their own domain pass DKIM and fail DMARC.
2 min readWhy DKIM signatures break in transit
Anything that modifies signed headers or the body invalidates the signature. Mailing lists are the usual culprit, and there is no way to sign around them.
2 min readWhat DMARC actually does
DMARC binds SPF and DKIM to the From address your recipients see, tells receivers what to do on failure, and sends you reports about it.
5 min readEvery DMARC tag, and which ones matter
A DMARC record has eleven possible tags. Four of them do the work; the rest are tuning you will rarely touch.
2 min readPublishing your first DMARC record
Start at p=none with a reporting address. It changes nothing about delivery and gives you the data you need for every decision that follows.
2 min readAlignment, the idea that makes DMARC work
Alignment requires the domain SPF or DKIM authenticated to be the domain your recipient sees. Without it, authentication proves nothing useful.
5 min readReading a DMARC aggregate report
The XML is dense but the structure is simple: who sent, from where, how much, and what the checks said. Here is how to turn it into a decision.
5 min readMoving from p=none to p=reject safely
Enforcement is a staged rollout driven by reports, not a flag you flip. Here is the sequence, and the signals that say you are ready for the next step.
5 min readSubdomains, sp= and the domains you forgot
A DMARC record on the parent domain covers every subdomain by default. That is usually what you want, and occasionally exactly what breaks things.
1 min readDMARC failure reports and the ruf= tag
Forensic reports carry real message data, one per failure. Few receivers send them and the privacy cost is real, but they answer what aggregates cannot.
1 min readDNS hygiene for email administrators
TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.
2 min readLocking down domains that never send mail
Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.
2 min readA monthly email authentication checklist
Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.
2 min read