SPF, DKIM and DMARC explained
Anyone can put your address in the “From” line of an email. SPF, DKIM and DMARC are DNS records that let receiving mail servers check whether a message really came from you. Without them, your genuine email is more likely to land in junk folders, and scammers find it easier to send mail pretending to be you.
What each record does
Section titled “What each record does”| Record | What it says | Where it lives |
|---|---|---|
| SPF | Which servers are allowed to send email for your domain | A TXT record on the domain itself, starting v=spf1 |
| DKIM | A public key that receivers use to check the digital signature added to every message you send | A TXT record on a name like selector._domainkey.example.com |
| DMARC | What receivers should do with mail that fails SPF and DKIM, and where to send reports | A TXT record on _dmarc.example.com, starting v=DMARC1 |
They work together. SPF and DKIM each prove something about a message; DMARC tells the world how strict to be when those checks fail.
Sheernox sets them up for you
Section titled “Sheernox sets them up for you”When your domain’s email is hosted with Sheernox, SPF, DKIM (with a 2048-bit key) and DMARC records are created for it automatically. If your domain also uses Sheernox nameservers, those records are published for you and there is nothing else to do.
Use only one SPF record
Section titled “Use only one SPF record”A domain must have exactly one SPF record. If you also send email through another service, such as a newsletter platform or a help desk, do not add a second v=spf1 record. Instead, add that service’s include: to your existing SPF record. Two SPF records make SPF fail for every message.
Check your records
Section titled “Check your records”-
Open a public DNS lookup tool, or use a terminal.
-
Look up the
TXTrecords for your domain and for_dmarc.followed by your domain:Terminal window dig +short TXT example.comdig +short TXT _dmarc.example.comReplace
example.comwith your domain. On Windows, usenslookup -type=TXT example.cominstead ofdig. -
Confirm you see one record starting
v=spf1and one startingv=DMARC1. -
To check DKIM, send a message from your mailbox to an address at a large provider such as Gmail, open it, and view the original message. The authentication results should show
dkim=pass,spf=passanddmarc=pass.
If any check fails, open a ticket with the domain name and, if you can, the full headers of a test message.