Email authentication in plain English
SPF, DKIM and DMARC are three DNS records answering one question for a receiving server: should this message, claiming to be from your domain, be trusted?
Anyone can put your domain in the From header of an email. SMTP was designed in an era where that was not a problem, and it has no built-in notion of identity. Email authentication is the set of DNS records that bolt identity on afterwards.
The three records
- SPF lists the servers allowed to send mail for your domain. The receiver compares the connecting IP against that list.
- DKIM attaches a cryptographic signature to each message. The receiver fetches your public key from DNS and verifies the signature held.
- DMARC ties the first two to the address your recipients actually see, and tells receivers what to do when neither one lines up.
SPF and DKIM are independent checks. DMARC is the policy layer on top: it only passes if at least one of SPF or DKIM passes and is aligned with the visible From domain. That alignment requirement is the whole point. Without it, an attacker could pass SPF for their own domain while still displaying yours.
Where they live
The three lookups a receiver makes
example.com TXT v=spf1 include:_spf.google.com -all
selector1._domainkey.example.com TXT v=DKIM1; k=rsa; p=MIIBIjANBg...
_dmarc.example.com TXT v=DMARC1; p=reject; rua=mailto:dmarc@example.comThe order to deploy them
- Publish SPF listing every service that sends as your domain.
- Turn on DKIM signing at each of those services and publish their public keys.
- Publish DMARC at p=none with a rua address, and read the reports for a few weeks.
- Tighten to quarantine, then reject, once the reports show only your own senders passing.
Do not start at p=reject. A DMARC policy is enforced against every sender, including the billing system nobody remembered. Start at none and let the reports find them for you.
More on Fundamentals
DNS hygiene for email administrators
TTLs, string limits, propagation and stale records cause more email incidents than the protocols themselves. A short checklist for keeping the zone honest.
Locking down domains that never send mail
Parked domains, redirect domains and internal subdomains are spoofed precisely because nobody protects them. Three records fix it permanently.
A monthly email authentication checklist
Authentication is not a project you finish. Thirty minutes a month keeps SPF, DKIM and DMARC from drifting out from under you.