Email Marketing & AutomationDeliverability · Lesson 3 of 16

Authentication: SPF, DKIM and DMARC

Article · 16 min · 8 min lecture

Video lecture

SPF, DKIM and DMARC: proving your email is really from you

11 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 11

Authentication

  • SPF, DKIM, DMARC
  • Alignment
  • DNS records
  • Checking and reports
  • Moving to enforcement

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Deliverability is the foundation

An email that lands in spam, or is rejected, earns nothing. Deliverability is the ability to reach the inbox. It depends on three things: authentication (proving you are who you say you are), reputation (how recipients and mailbox providers judge your sending) and content and engagement (whether people want your email).

The three authentication standards

SPF (Sender Policy Framework) A DNS TXT record listing which servers are allowed to send email for your domain. Example:

v=spf1 include:_spf.google.com include:sendgrid.net ~all
  • One SPF record per domain (combine includes into one record).
  • There is a limit of 10 DNS lookups; too many includes can break SPF.

DKIM (DomainKeys Identified Mail) A digital signature added to each email, verified with a public key published in your DNS. It proves the message was authorised by the domain and not altered in transit. Your email platform provides the DKIM records to add. Use a key length of at least 1024 bits (2048 recommended where supported).

DMARC (Domain-based Message Authentication, Reporting and Conformance) A DNS policy that tells receivers what to do when an email fails authentication, and where to send reports. Example:

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
  • p=none: monitor only.
  • p=quarantine: send failing mail to spam.
  • p=reject: block failing mail.

DMARC requires alignment: the domain in the visible "From" address must match (align with) the domain authenticated by SPF or DKIM. This is why you should send from your own domain with custom DKIM, not a platform's shared domain.

Mailbox provider requirements

Since 2024, Google and Yahoo have required bulk senders (Google defines this as sending close to 5,000 or more messages a day to Gmail accounts) to:

  • Authenticate with SPF and DKIM, and publish a DMARC policy (at least p=none) with alignment.
  • Offer one-click unsubscribe in marketing messages (the List-Unsubscribe header) and honour unsubscribes within two days.
  • Keep reported spam complaint rates low – Google advises staying below 0.1% and never reaching 0.3% or higher.

Microsoft introduced similar requirements for high-volume senders to Outlook.com addresses in 2025. Even if you send less, following these rules is best practice and protects your domain.

Setting it up: a practical sequence

  1. Use a domain you control (for example news.yourbrand.com or yourbrand.com), never a free Gmail or Yahoo address as the sender for bulk email.
  2. Add SPF including your email platform.
  3. Add DKIM records supplied by your email platform.
  4. Add DMARC with p=none and a reporting address; use a DMARC reporting tool to read the reports.
  5. Review reports for a few weeks to find legitimate services failing authentication (for example your invoicing tool or CRM).
  6. Tighten gradually to p=quarantine, then p=reject, once all legitimate sources pass.
  7. Consider a subdomain for marketing email to separate its reputation from your team's everyday email.

Warming up a new domain or IP

Mailbox providers are cautious with senders they do not know. When starting with a new domain or dedicated IP, warm up: start by sending to your most engaged subscribers in smaller volumes, then increase gradually over several weeks. Sudden large sends from a new domain look like spam behaviour.

Tools to check

  • Your email platform's domain authentication page.
  • DNS lookup and DMARC checking tools.
  • Google Postmaster Tools for spam rate and authentication data at Gmail.
  • Microsoft SNDS for Outlook-related data.

Worked example

A Dubai events company sends newsletters from info@company.ae via an email platform without custom DKIM. Gmail users see "via platform.com" and many emails go to spam. The team adds SPF and DKIM for the platform, publishes DMARC with p=none, discovers their ticketing tool also sends as the domain and authenticates it too, then moves to p=quarantine after a month. Inbox placement and click rates improve.

Common mistakes

  • Multiple SPF records on one domain.
  • Sending from a free mailbox address.
  • Jumping straight to p=reject and blocking legitimate email.
  • Blasting a new domain with a large list on day one.

Hands-on: a complete DNS record set (example)

For a brand sending staff email through Google Workspace and marketing email through an email platform on the subdomain news.example.com (values are illustrative – always copy the exact records your providers give you):

; SPF for the root domain (staff email)
example.com.            TXT   "v=spf1 include:_spf.google.com ~all"

; SPF for the marketing subdomain (your ESP gives the include or a CNAME)
news.example.com.       TXT   "v=spf1 include:spf.your-esp.example ~all"

; DKIM – usually CNAMEs pointing to keys your providers host and rotate
google._domainkey.example.com.   TXT    "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
esp1._domainkey.news.example.com. CNAME esp1.dkim.your-esp.example.

; DMARC – start with monitoring, reports to a mailbox or reporting service
_dmarc.example.com.     TXT   "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=r; aspf=r; fo=1"

; Later, once reports are clean (applies to subdomains too unless sp= is set)
_dmarc.example.com.     TXT   "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"
_dmarc.example.com.     TXT   "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"

Key tags: p = policy for the domain; sp = policy for subdomains; rua = where aggregate reports go; adkim/aspf = relaxed (r) or strict (s) alignment; pct = percentage of failing mail the policy applies to (use it to phase in quarantine). Only one DMARC record and one SPF record may exist per name.

Check your records from a terminal

dig +short TXT example.com | grep spf1
dig +short TXT _dmarc.example.com
dig +short TXT google._domainkey.example.com
# Windows PowerShell alternative:
# Resolve-DnsName -Type TXT _dmarc.example.com

Then send a test email to a Gmail account, open it, choose Show original, and confirm SPF: PASS, DKIM: PASS, DMARC: PASS.

Reading DMARC reports

Aggregate (rua) reports are XML files listing every source that sent mail using your domain, how many messages, and whether SPF and DKIM passed and aligned. Reading raw XML is painful; use a DMARC reporting service or your email platform's DMARC dashboard. Look for:

  • Legitimate sources failing (your CRM, invoicing tool, helpdesk) → authenticate them.
  • Unknown sources sending as you → possible spoofing; moving to p=reject protects you.

Worked example 2: a Lahore Shopify brand

A Lahore brand uses Google Workspace, Shopify order emails and Klaviyo for marketing. It adds Klaviyo's branded sending domain (send.brand.pk) with its DKIM and SPF records, turns on Shopify's sender domain authentication, and publishes DMARC at p=none with a reporting service. Reports show a courier-tracking tool sending as the domain without DKIM; the team configures it. After four weeks of clean reports, DMARC moves to p=quarantine; pct=25, then 100%, then p=reject. Gmail placement improves and spoofed "order update" scams using the brand's domain are blocked.

How to measure success

  • 100% of legitimate mail passing SPF or DKIM with alignment in DMARC reports.
  • DMARC at p=quarantine or p=reject (also required for BIMI – next lesson).
  • Authentication shown as passing in Google Postmaster Tools, with no unexplained sources in reports.

Key takeaways

  • Deliverability depends on authentication, reputation and wanted content.
  • SPF lists authorised senders, DKIM signs messages and DMARC sets policy and reporting with alignment.
  • Bulk senders to Gmail and Yahoo must authenticate, offer one-click unsubscribe and keep complaint rates low; Microsoft has similar rules.
  • Move DMARC from p=none to quarantine and reject gradually, and warm up new domains with engaged subscribers.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which record tells receiving servers what to do when an email fails authentication?
  2. What does DKIM provide?
  3. A new sending domain needs to reach 50,000 subscribers. What is the best approach?

Put it into practice

Look up the SPF, DKIM and DMARC records of a domain you manage (or a brand you like) using a free DNS tool, and note what policy it uses and any issues.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.