Email Marketing & AutomationDeliverability · Lesson 3 of 16
Authentication: SPF, DKIM and DMARC
Video lecture
SPF, DKIM and DMARC: proving your email is really from you
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Authentication
Imagine posting a letter with no return address, no signature and no official seal. Would the receptionist at a big company trust it enough to put it on the boss's desk? Probably not. Mailbox providers like Gmail, Yahoo and Outlook face that decision billions of times a day. Authentication is how you prove your email really comes from you. In this lecture you'll learn what SPF, DKIM and DMARC do, how alignment works, the exact DNS records to publish, how to check them, how to read DMARC reports, and how to move safely from monitoring to full protection.
0:43 Deliverability = 3 things
First, why this matters. Deliverability, reaching the inbox, depends on three things. Authentication: proving you are who you say you are. Reputation: how recipients and mailbox providers judge your sending over time. And content and engagement: whether people want your email. Authentication is the foundation, because without it, the other two barely count. And since twenty twenty-four, Google and Yahoo have required bulk senders to authenticate properly, and Microsoft followed for high-volume senders to Outlook addresses in twenty twenty-five. So this isn't optional anymore. It's the entry ticket.
1:21 The three standards
Let's meet the three standards. SPF, Sender Policy Framework, is a DNS text record listing which servers are allowed to send email for your domain. Think of it as a guest list at the door. DKIM, DomainKeys Identified Mail, adds a digital signature to every email, checked against a public key in your DNS. It proves the message was authorised by your domain and wasn't altered on the way. Think of it as a wax seal. And DMARC tells receivers what to do when an email fails those checks, and where to send reports. It's the security policy: let it in, send it to spam, or turn it away.
2:08 Alignment
Now the concept that trips most people up: alignment. DMARC doesn't just ask whether SPF or DKIM passed. It asks whether they passed for the same domain the reader sees in the From address. If your email says it's from hello at yourbrand dot com, but it's DKIM-signed by your email platform's shared domain, DKIM passes, but it doesn't align, so DMARC can fail. That's why you should set up custom DKIM, often called a branded or authenticated sending domain, for every service that sends as you: your email platform, your store, your CRM, your helpdesk.
2:50 Hands-on: DNS records
Let's look at real records. The lesson text has a complete example set. For SPF, one text record per domain, like v equals spf1, include Google's servers, tilde all. Only one SPF record per name, and watch the ten DNS lookup limit, because too many includes break SPF. For DKIM, your providers usually give you CNAME records that point to keys they host and rotate. And for DMARC, a text record at underscore dmarc: v equals DMARC1, p equals none, and a rua address for reports. Start with p equals none, which only monitors. Later you'll move to quarantine and then reject.
3:34 Check your setup
How do you check them? From a terminal, the dig command shows your records: dig short TXT on your domain for SPF, on underscore dmarc for DMARC, and on your DKIM selector. On Windows, Resolve DNS Name does the same. Then the real test: send an email to a Gmail account, open it, choose show original, and look for three words next to SPF, DKIM and DMARC: pass, pass, pass. If any says fail, fix it before you send a campaign. It takes two minutes and prevents weeks of mysterious spam-folder problems.
4:14 Safe rollout
Now the safe rollout sequence. Use a domain you control, never a free Gmail or Yahoo address, for bulk email. Add SPF including your email platform. Add the DKIM records your providers give you. Publish DMARC at p equals none with a reporting address, and use a DMARC reporting service to read the reports, because raw reports are XML files. Review them for a few weeks to find legitimate services failing, like your invoicing tool, CRM or helpdesk. Fix them. Then tighten gradually to quarantine, using the pct tag to phase it in, and then to reject. And consider a subdomain for marketing to separate its reputation from your team's everyday email.
5:03 Example 1: Dubai events company
Let's do a simple worked example. A Dubai events company sends newsletters from info at company dot a e, through an email platform without custom DKIM. Gmail users see via platform dot com next to the sender name, and many emails land in spam. The team adds SPF and DKIM for the platform, publishes DMARC at p equals none, and discovers from the reports that their ticketing tool also sends as the domain without authentication. They fix that too. A month later they move to quarantine. Inbox placement and click rates improve, and the via label disappears.
5:45 Example 2: Lahore Shopify brand (illustrative)
Now a realistic scenario. A Lahore brand uses Google Workspace for staff email, Shopify for order emails, and Klaviyo for marketing. It sets up Klaviyo's branded sending domain on a subdomain, send dot brand dot p k, with its DKIM and SPF records, turns on Shopify's sender domain authentication, and publishes DMARC at p equals none with a reporting service. The reports reveal a courier-tracking tool sending as the domain without DKIM, so they configure it. After four clean weeks, DMARC goes to quarantine at twenty-five percent, then a hundred, then reject. Gmail placement improves, and scammers can no longer send fake order updates using the brand's domain.
6:32 Warm-up, mistakes, success
Two more things. Warm up new domains or dedicated IP addresses: start by sending to your most engaged subscribers in smaller volumes, then increase gradually over several weeks, because sudden large sends from an unknown domain look like spam. And the common mistakes: multiple SPF records on one domain, sending from a free mailbox address, jumping straight to p equals reject and blocking legitimate email, and blasting a new domain with a big list on day one. How do you measure success? All legitimate mail passing with alignment in your DMARC reports, a policy of quarantine or reject, and no unexplained sources.
7:16 Recap and try this now
Let's recap. Deliverability starts with authentication. SPF lists who may send for your domain, DKIM signs each message, and DMARC sets the policy and sends you reports, with alignment tying them to your visible From address. Publish one SPF record, custom DKIM for every sender, and DMARC starting at none, then move to quarantine and reject as reports come back clean. Check with dig and Gmail's show original. Here's your try this now. Look up the SPF, DKIM and DMARC records for a domain you manage, or a brand you like, using the commands in the lesson text. Note the DMARC policy and any problems you spot.
Deliverability is the foundation
An email that lands in spam, or is rejected, earns nothing. Deliverability is the ability to reach the inbox. It depends on three things: authentication (proving you are who you say you are), reputation (how recipients and mailbox providers judge your sending) and content and engagement (whether people want your email).
The three authentication standards
SPF (Sender Policy Framework) A DNS TXT record listing which servers are allowed to send email for your domain. Example:
v=spf1 include:_spf.google.com include:sendgrid.net ~all- One SPF record per domain (combine includes into one record).
- There is a limit of 10 DNS lookups; too many includes can break SPF.
DKIM (DomainKeys Identified Mail) A digital signature added to each email, verified with a public key published in your DNS. It proves the message was authorised by the domain and not altered in transit. Your email platform provides the DKIM records to add. Use a key length of at least 1024 bits (2048 recommended where supported).
DMARC (Domain-based Message Authentication, Reporting and Conformance) A DNS policy that tells receivers what to do when an email fails authentication, and where to send reports. Example:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com- p=none: monitor only.
- p=quarantine: send failing mail to spam.
- p=reject: block failing mail.
DMARC requires alignment: the domain in the visible "From" address must match (align with) the domain authenticated by SPF or DKIM. This is why you should send from your own domain with custom DKIM, not a platform's shared domain.
Mailbox provider requirements
Since 2024, Google and Yahoo have required bulk senders (Google defines this as sending close to 5,000 or more messages a day to Gmail accounts) to:
- Authenticate with SPF and DKIM, and publish a DMARC policy (at least p=none) with alignment.
- Offer one-click unsubscribe in marketing messages (the List-Unsubscribe header) and honour unsubscribes within two days.
- Keep reported spam complaint rates low – Google advises staying below 0.1% and never reaching 0.3% or higher.
Microsoft introduced similar requirements for high-volume senders to Outlook.com addresses in 2025. Even if you send less, following these rules is best practice and protects your domain.
Setting it up: a practical sequence
- Use a domain you control (for example
news.yourbrand.comoryourbrand.com), never a free Gmail or Yahoo address as the sender for bulk email. - Add SPF including your email platform.
- Add DKIM records supplied by your email platform.
- Add DMARC with p=none and a reporting address; use a DMARC reporting tool to read the reports.
- Review reports for a few weeks to find legitimate services failing authentication (for example your invoicing tool or CRM).
- Tighten gradually to p=quarantine, then p=reject, once all legitimate sources pass.
- Consider a subdomain for marketing email to separate its reputation from your team's everyday email.
Warming up a new domain or IP
Mailbox providers are cautious with senders they do not know. When starting with a new domain or dedicated IP, warm up: start by sending to your most engaged subscribers in smaller volumes, then increase gradually over several weeks. Sudden large sends from a new domain look like spam behaviour.
Tools to check
- Your email platform's domain authentication page.
- DNS lookup and DMARC checking tools.
- Google Postmaster Tools for spam rate and authentication data at Gmail.
- Microsoft SNDS for Outlook-related data.
Worked example
A Dubai events company sends newsletters from info@company.ae via an email platform without custom DKIM. Gmail users see "via platform.com" and many emails go to spam. The team adds SPF and DKIM for the platform, publishes DMARC with p=none, discovers their ticketing tool also sends as the domain and authenticates it too, then moves to p=quarantine after a month. Inbox placement and click rates improve.
Common mistakes
- Multiple SPF records on one domain.
- Sending from a free mailbox address.
- Jumping straight to p=reject and blocking legitimate email.
- Blasting a new domain with a large list on day one.
Hands-on: a complete DNS record set (example)
For a brand sending staff email through Google Workspace and marketing email through an email platform on the subdomain news.example.com (values are illustrative – always copy the exact records your providers give you):
; SPF for the root domain (staff email)
example.com. TXT "v=spf1 include:_spf.google.com ~all"
; SPF for the marketing subdomain (your ESP gives the include or a CNAME)
news.example.com. TXT "v=spf1 include:spf.your-esp.example ~all"
; DKIM – usually CNAMEs pointing to keys your providers host and rotate
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
esp1._domainkey.news.example.com. CNAME esp1.dkim.your-esp.example.
; DMARC – start with monitoring, reports to a mailbox or reporting service
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=r; aspf=r; fo=1"
; Later, once reports are clean (applies to subdomains too unless sp= is set)
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"Key tags: p = policy for the domain; sp = policy for subdomains; rua = where aggregate reports go; adkim/aspf = relaxed (r) or strict (s) alignment; pct = percentage of failing mail the policy applies to (use it to phase in quarantine). Only one DMARC record and one SPF record may exist per name.
Check your records from a terminal
dig +short TXT example.com | grep spf1
dig +short TXT _dmarc.example.com
dig +short TXT google._domainkey.example.com
# Windows PowerShell alternative:
# Resolve-DnsName -Type TXT _dmarc.example.comThen send a test email to a Gmail account, open it, choose Show original, and confirm SPF: PASS, DKIM: PASS, DMARC: PASS.
Reading DMARC reports
Aggregate (rua) reports are XML files listing every source that sent mail using your domain, how many messages, and whether SPF and DKIM passed and aligned. Reading raw XML is painful; use a DMARC reporting service or your email platform's DMARC dashboard. Look for:
- Legitimate sources failing (your CRM, invoicing tool, helpdesk) → authenticate them.
- Unknown sources sending as you → possible spoofing; moving to
p=rejectprotects you.
Worked example 2: a Lahore Shopify brand
A Lahore brand uses Google Workspace, Shopify order emails and Klaviyo for marketing. It adds Klaviyo's branded sending domain (send.brand.pk) with its DKIM and SPF records, turns on Shopify's sender domain authentication, and publishes DMARC at p=none with a reporting service. Reports show a courier-tracking tool sending as the domain without DKIM; the team configures it. After four weeks of clean reports, DMARC moves to p=quarantine; pct=25, then 100%, then p=reject. Gmail placement improves and spoofed "order update" scams using the brand's domain are blocked.
How to measure success
- 100% of legitimate mail passing SPF or DKIM with alignment in DMARC reports.
- DMARC at
p=quarantineorp=reject(also required for BIMI – next lesson). - Authentication shown as passing in Google Postmaster Tools, with no unexplained sources in reports.
Key takeaways
- Deliverability depends on authentication, reputation and wanted content.
- SPF lists authorised senders, DKIM signs messages and DMARC sets policy and reporting with alignment.
- Bulk senders to Gmail and Yahoo must authenticate, offer one-click unsubscribe and keep complaint rates low; Microsoft has similar rules.
- Move DMARC from p=none to quarantine and reject gradually, and warm up new domains with engaged subscribers.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Look up the SPF, DKIM and DMARC records of a domain you manage (or a brand you like) using a free DNS tool, and note what policy it uses and any issues.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.