SPF, DKIM & DMARC Tips
25 articles on the everyday administration of SPF, DKIM and DMARC. Reading records, rolling out policy, working through reports, and the mistakes that break mail without anyone noticing. Written to be read in order, but each one stands alone.
What SPF actually does
SPF authorises servers, not messages, and it checks the envelope sender rather than the From address your recipient sees. That explains most SPF confusion.
Start readingReading an SPF record, mechanism by mechanism
A walk through every mechanism and modifier you are likely to meet in a real SPF record.
2 min readThe SPF ten-lookup limit, and how to stay under it
SPF evaluation is capped at ten DNS lookups. Exceed it and the result is permerror, which most receivers treat as a failure, including DMARC.
4 min read-all or ~all: choosing your SPF policy
Hardfail rejects unlisted senders outright; softfail marks them and delivers anyway. Which you want depends on how complete your record already is.
2 min readSeven SPF mistakes that break mail quietly
Most broken SPF records look fine at a glance. These are the failure modes that pass visual inspection and still cost you delivery.
2 min readAdding a new sender to SPF safely
A short routine for onboarding a new mail vendor: check the lookup budget first, publish second, verify third.
2 min readWhy SPF fails on forwarded mail
Forwarding rewrites the path but not the sender, so SPF sees the wrong IP. Understanding this stops you chasing a bug that is working as designed.
2 min read