---
title: "Authentication: SPF, DKIM and DMARC | Optimize All Academy"
description: "Deliverability is the foundation An email that lands in spam, or is rejected, earns nothing. Deliverability is the ability to reach the inbox. It depends…"
url: https://optimizeall.com/learn/email-marketing-and-automation/authentication-spf-dkim-dmarc
updated: 2026-10-05
---

Email Marketing & Automation · Deliverability · lesson 3 of 16 · 16 min

# Authentication: SPF, DKIM and DMARC

## Deliverability is the foundation

An email that lands in spam, or is rejected, earns nothing. **Deliverability** is the ability to reach the inbox. It depends on three things: **authentication** (proving you are who you say you are), **reputation** (how recipients and mailbox providers judge your sending) and **content and engagement** (whether people want your email).

## The three authentication standards

**SPF (Sender Policy Framework)**
A DNS TXT record listing which servers are allowed to send email for your domain. Example:

```
v=spf1 include:_spf.google.com include:sendgrid.net ~all
```

- One SPF record per domain (combine includes into one record).
- There is a limit of 10 DNS lookups; too many includes can break SPF.

**DKIM (DomainKeys Identified Mail)**
A digital signature added to each email, verified with a public key published in your DNS. It proves the message was authorised by the domain and not altered in transit. Your email platform provides the DKIM records to add. Use a key length of at least 1024 bits (2048 recommended where supported).

**DMARC (Domain-based Message Authentication, Reporting and Conformance)**
A DNS policy that tells receivers what to do when an email fails authentication, and where to send reports. Example:

```
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
```

- **p=none:** monitor only.
- **p=quarantine:** send failing mail to spam.
- **p=reject:** block failing mail.

DMARC requires **alignment**: the domain in the visible "From" address must match (align with) the domain authenticated by SPF or DKIM. This is why you should send from your own domain with custom DKIM, not a platform's shared domain.

## Mailbox provider requirements

Since 2024, Google and Yahoo have required bulk senders (Google defines this as sending close to 5,000 or more messages a day to Gmail accounts) to:

- Authenticate with **SPF and DKIM**, and publish a **DMARC** policy (at least p=none) with alignment.
- Offer **one-click unsubscribe** in marketing messages (the List-Unsubscribe header) and honour unsubscribes within two days.
- Keep reported **spam complaint rates low** – Google advises staying below 0.1% and never reaching 0.3% or higher.

Microsoft introduced similar requirements for high-volume senders to Outlook.com addresses in 2025. Even if you send less, following these rules is best practice and protects your domain.

## Setting it up: a practical sequence

1. **Use a domain you control** (for example `news.yourbrand.com` or `yourbrand.com`), never a free Gmail or Yahoo address as the sender for bulk email.
2. **Add SPF** including your email platform.
3. **Add DKIM** records supplied by your email platform.
4. **Add DMARC with p=none** and a reporting address; use a DMARC reporting tool to read the reports.
5. **Review reports** for a few weeks to find legitimate services failing authentication (for example your invoicing tool or CRM).
6. **Tighten gradually** to p=quarantine, then p=reject, once all legitimate sources pass.
7. Consider a **subdomain** for marketing email to separate its reputation from your team's everyday email.

## Warming up a new domain or IP

Mailbox providers are cautious with senders they do not know. When starting with a new domain or dedicated IP, **warm up**: start by sending to your most engaged subscribers in smaller volumes, then increase gradually over several weeks. Sudden large sends from a new domain look like spam behaviour.

## Tools to check

- Your email platform's domain authentication page.
- DNS lookup and DMARC checking tools.
- **Google Postmaster Tools** for spam rate and authentication data at Gmail.
- **Microsoft SNDS** for Outlook-related data.

## Worked example

A Dubai events company sends newsletters from `info@company.ae` via an email platform without custom DKIM. Gmail users see "via platform.com" and many emails go to spam. The team adds SPF and DKIM for the platform, publishes DMARC with p=none, discovers their ticketing tool also sends as the domain and authenticates it too, then moves to p=quarantine after a month. Inbox placement and click rates improve.

## Common mistakes

- Multiple SPF records on one domain.
- Sending from a free mailbox address.
- Jumping straight to p=reject and blocking legitimate email.
- Blasting a new domain with a large list on day one.

## Hands-on: a complete DNS record set (example)

For a brand sending staff email through Google Workspace and marketing email through an email platform on the subdomain `news.example.com` (values are illustrative – always copy the exact records your providers give you):

```text
; SPF for the root domain (staff email)
example.com.            TXT   "v=spf1 include:_spf.google.com ~all"

; SPF for the marketing subdomain (your ESP gives the include or a CNAME)
news.example.com.       TXT   "v=spf1 include:spf.your-esp.example ~all"

; DKIM – usually CNAMEs pointing to keys your providers host and rotate
google._domainkey.example.com.   TXT    "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
esp1._domainkey.news.example.com. CNAME esp1.dkim.your-esp.example.

; DMARC – start with monitoring, reports to a mailbox or reporting service
_dmarc.example.com.     TXT   "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=r; aspf=r; fo=1"

; Later, once reports are clean (applies to subdomains too unless sp= is set)
_dmarc.example.com.     TXT   "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"
_dmarc.example.com.     TXT   "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"
```

Key tags: `p` = policy for the domain; `sp` = policy for subdomains; `rua` = where aggregate reports go; `adkim`/`aspf` = relaxed (`r`) or strict (`s`) alignment; `pct` = percentage of failing mail the policy applies to (use it to phase in quarantine). Only one DMARC record and one SPF record may exist per name.

## Check your records from a terminal

```bash
dig +short TXT example.com | grep spf1
dig +short TXT _dmarc.example.com
dig +short TXT google._domainkey.example.com
# Windows PowerShell alternative:
# Resolve-DnsName -Type TXT _dmarc.example.com
```

Then send a test email to a Gmail account, open it, choose **Show original**, and confirm **SPF: PASS, DKIM: PASS, DMARC: PASS**.

## Reading DMARC reports

Aggregate (`rua`) reports are XML files listing every source that sent mail using your domain, how many messages, and whether SPF and DKIM passed and aligned. Reading raw XML is painful; use a DMARC reporting service or your email platform's DMARC dashboard. Look for:

- **Legitimate sources failing** (your CRM, invoicing tool, helpdesk) → authenticate them.
- **Unknown sources** sending as you → possible spoofing; moving to `p=reject` protects you.

## Worked example 2: a Lahore Shopify brand

A Lahore brand uses Google Workspace, Shopify order emails and Klaviyo for marketing. It adds Klaviyo's branded sending domain (`send.brand.pk`) with its DKIM and SPF records, turns on Shopify's sender domain authentication, and publishes DMARC at `p=none` with a reporting service. Reports show a courier-tracking tool sending as the domain without DKIM; the team configures it. After four weeks of clean reports, DMARC moves to `p=quarantine; pct=25`, then 100%, then `p=reject`. Gmail placement improves and spoofed "order update" scams using the brand's domain are blocked.

## How to measure success

- 100% of legitimate mail passing SPF or DKIM **with alignment** in DMARC reports.
- DMARC at `p=quarantine` or `p=reject` (also required for BIMI – next lesson).
- Authentication shown as passing in Google Postmaster Tools, with no unexplained sources in reports.

## Video lecture: SPF, DKIM and DMARC: proving your email is really from you

Lecture coming soon · 11 chapters · about 8 minutes. Read the full transcript below.

1. Authentication
2. Deliverability = 3 things
3. The three standards
4. Alignment
5. Hands-on: DNS records
6. Check your setup
7. Safe rollout
8. Example 1: Dubai events company
9. Example 2: Lahore Shopify brand (illustrative)
10. Warm-up, mistakes, success
11. Recap and try this now

## Lecture transcript

### Authentication

Imagine posting a letter with no return address, no signature and no official seal. Would the receptionist at a big company trust it enough to put it on the boss's desk? Probably not. Mailbox providers like Gmail, Yahoo and Outlook face that decision billions of times a day. Authentication is how you prove your email really comes from you. In this lecture you'll learn what SPF, DKIM and DMARC do, how alignment works, the exact DNS records to publish, how to check them, how to read DMARC reports, and how to move safely from monitoring to full protection.

### Deliverability = 3 things

First, why this matters. Deliverability, reaching the inbox, depends on three things. Authentication: proving you are who you say you are. Reputation: how recipients and mailbox providers judge your sending over time. And content and engagement: whether people want your email. Authentication is the foundation, because without it, the other two barely count. And since twenty twenty-four, Google and Yahoo have required bulk senders to authenticate properly, and Microsoft followed for high-volume senders to Outlook addresses in twenty twenty-five. So this isn't optional anymore. It's the entry ticket.

### The three standards

Let's meet the three standards. SPF, Sender Policy Framework, is a DNS text record listing which servers are allowed to send email for your domain. Think of it as a guest list at the door. DKIM, DomainKeys Identified Mail, adds a digital signature to every email, checked against a public key in your DNS. It proves the message was authorised by your domain and wasn't altered on the way. Think of it as a wax seal. And DMARC tells receivers what to do when an email fails those checks, and where to send reports. It's the security policy: let it in, send it to spam, or turn it away.

### Alignment

Now the concept that trips most people up: alignment. DMARC doesn't just ask whether SPF or DKIM passed. It asks whether they passed for the same domain the reader sees in the From address. If your email says it's from hello at yourbrand dot com, but it's DKIM-signed by your email platform's shared domain, DKIM passes, but it doesn't align, so DMARC can fail. That's why you should set up custom DKIM, often called a branded or authenticated sending domain, for every service that sends as you: your email platform, your store, your CRM, your helpdesk.

### Hands-on: DNS records

Let's look at real records. The lesson text has a complete example set. For SPF, one text record per domain, like v equals spf1, include Google's servers, tilde all. Only one SPF record per name, and watch the ten DNS lookup limit, because too many includes break SPF. For DKIM, your providers usually give you CNAME records that point to keys they host and rotate. And for DMARC, a text record at underscore dmarc: v equals DMARC1, p equals none, and a rua address for reports. Start with p equals none, which only monitors. Later you'll move to quarantine and then reject.

### Check your setup

How do you check them? From a terminal, the dig command shows your records: dig short TXT on your domain for SPF, on underscore dmarc for DMARC, and on your DKIM selector. On Windows, Resolve DNS Name does the same. Then the real test: send an email to a Gmail account, open it, choose show original, and look for three words next to SPF, DKIM and DMARC: pass, pass, pass. If any says fail, fix it before you send a campaign. It takes two minutes and prevents weeks of mysterious spam-folder problems.

### Safe rollout

Now the safe rollout sequence. Use a domain you control, never a free Gmail or Yahoo address, for bulk email. Add SPF including your email platform. Add the DKIM records your providers give you. Publish DMARC at p equals none with a reporting address, and use a DMARC reporting service to read the reports, because raw reports are XML files. Review them for a few weeks to find legitimate services failing, like your invoicing tool, CRM or helpdesk. Fix them. Then tighten gradually to quarantine, using the pct tag to phase it in, and then to reject. And consider a subdomain for marketing to separate its reputation from your team's everyday email.

### Example 1: Dubai events company

Let's do a simple worked example. A Dubai events company sends newsletters from info at company dot a e, through an email platform without custom DKIM. Gmail users see via platform dot com next to the sender name, and many emails land in spam. The team adds SPF and DKIM for the platform, publishes DMARC at p equals none, and discovers from the reports that their ticketing tool also sends as the domain without authentication. They fix that too. A month later they move to quarantine. Inbox placement and click rates improve, and the via label disappears.

### Example 2: Lahore Shopify brand (illustrative)

Now a realistic scenario. A Lahore brand uses Google Workspace for staff email, Shopify for order emails, and Klaviyo for marketing. It sets up Klaviyo's branded sending domain on a subdomain, send dot brand dot p k, with its DKIM and SPF records, turns on Shopify's sender domain authentication, and publishes DMARC at p equals none with a reporting service. The reports reveal a courier-tracking tool sending as the domain without DKIM, so they configure it. After four clean weeks, DMARC goes to quarantine at twenty-five percent, then a hundred, then reject. Gmail placement improves, and scammers can no longer send fake order updates using the brand's domain.

### Warm-up, mistakes, success

Two more things. Warm up new domains or dedicated IP addresses: start by sending to your most engaged subscribers in smaller volumes, then increase gradually over several weeks, because sudden large sends from an unknown domain look like spam. And the common mistakes: multiple SPF records on one domain, sending from a free mailbox address, jumping straight to p equals reject and blocking legitimate email, and blasting a new domain with a big list on day one. How do you measure success? All legitimate mail passing with alignment in your DMARC reports, a policy of quarantine or reject, and no unexplained sources.

### Recap and try this now

Let's recap. Deliverability starts with authentication. SPF lists who may send for your domain, DKIM signs each message, and DMARC sets the policy and sends you reports, with alignment tying them to your visible From address. Publish one SPF record, custom DKIM for every sender, and DMARC starting at none, then move to quarantine and reject as reports come back clean. Check with dig and Gmail's show original. Here's your try this now. Look up the SPF, DKIM and DMARC records for a domain you manage, or a brand you like, using the commands in the lesson text. Note the DMARC policy and any problems you spot.

## Key takeaways

- Deliverability depends on authentication, reputation and wanted content.
- SPF lists authorised senders, DKIM signs messages and DMARC sets policy and reporting with alignment.
- Bulk senders to Gmail and Yahoo must authenticate, offer one-click unsubscribe and keep complaint rates low; Microsoft has similar rules.
- Move DMARC from p=none to quarantine and reject gradually, and warm up new domains with engaged subscribers.

## Try it

Look up the SPF, DKIM and DMARC records of a domain you manage (or a brand you like) using a free DNS tool, and note what policy it uses and any issues.

- [Previous: Segmentation and personalisation](https://optimizeall.com/learn/email-marketing-and-automation/segmentation-and-personalisation)
- [Next: Google, Yahoo and Microsoft sender rules, one-click unsubscribe and BIMI](https://optimizeall.com/learn/email-marketing-and-automation/bulk-sender-requirements-and-bimi)
- [All lessons of Email Marketing & Automation](https://optimizeall.com/learn/email-marketing-and-automation)
