SPF, DKIM & DMARC Tips
25 articles on the everyday administration of SPF, DKIM and DMARC. Reading records, rolling out policy, working through reports, and the mistakes that break mail without anyone noticing. Written to be read in order, but each one stands alone.
What DMARC actually does
DMARC binds SPF and DKIM to the From address your recipients see, tells receivers what to do on failure, and sends you reports about it.
Start readingEvery DMARC tag, and which ones matter
A DMARC record has eleven possible tags. Four of them do the work; the rest are tuning you will rarely touch.
2 min readPublishing your first DMARC record
Start at p=none with a reporting address. It changes nothing about delivery and gives you the data you need for every decision that follows.
2 min readAlignment, the idea that makes DMARC work
Alignment requires the domain SPF or DKIM authenticated to be the domain your recipient sees. Without it, authentication proves nothing useful.
5 min readReading a DMARC aggregate report
The XML is dense but the structure is simple: who sent, from where, how much, and what the checks said. Here is how to turn it into a decision.
5 min readMoving from p=none to p=reject safely
Enforcement is a staged rollout driven by reports, not a flag you flip. Here is the sequence, and the signals that say you are ready for the next step.
5 min readSubdomains, sp= and the domains you forgot
A DMARC record on the parent domain covers every subdomain by default. That is usually what you want, and occasionally exactly what breaks things.
1 min readDMARC failure reports and the ruf= tag
Forensic reports carry real message data, one per failure. Few receivers send them and the privacy cost is real, but they answer what aggregates cannot.
1 min read