SPF vs DKIM vs DMARC: What Each One Does and Why You Need All Three
If you've looked into email security at all, you've seen the acronyms: SPF, DKIM, DMARC. They're almost always mentioned together, and for good reason — each one solves a different piece of the same problem, and none of them works fully on its own.
Here's what each record actually does and why you need all three.
SPF: Who is allowed to send?
SPF (Sender Policy Framework) is a DNS record that publishes a list of IP addresses authorized to send email from your domain. It's like a VIP list at the door of a club.
When a receiving server gets a message claiming to be from your domain, it checks the SPF record. If the sending IP is on the list, SPF passes. If not, it fails.
Example SPF record:
v=spf1 include:_spf.google.com include:sendgrid.net -all
This says: "Only Google Workspace and SendGrid are authorized to send email for this domain. Everyone else gets rejected."
SPF's weakness: forwarded mail. When an email is forwarded, the original sender's SPF check runs against the forwarding server's IP, which isn't authorized. So SPF breaks on forwarded mail — that's normal and expected.
DKIM: Is the email tamper-proof?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to the headers of every outgoing email. The signature is generated using a private key, and the public key is published as a DNS record.
When a receiving server gets your email, it looks up the public key, decrypts the signature, and verifies that the headers haven't been changed in transit. If they match, DKIM passes.
What DKIM survives: forwarding. Because the signature is embedded in the email itself (not tied to the sending server's IP), it stays valid even after the message is forwarded.
DKIM's weakness: a signature alone proves nothing about who sent the email. Anyone could technically add a DKIM signature — it's the domain in the d= tag that ties it to you.
DMARC: What happens when things fail?
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the policy layer that sits on top of SPF and DKIM. It tells receiving servers what to do with messages that fail authentication.
DMARC also checks alignment — it verifies that the domain in the "From" address matches the domain that passed SPF or DKIM. This is critical because without alignment, a spammer could use a different SPF-authorized service to send mail that appears to come from your domain.
The three DMARC policies:
p=none— monitor only, deliver everything (start here)p=quarantine— send failures to spamp=reject— block failures outright
Example DMARC record:
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com
Why you need all three
Think of it as a security system with three layers:
- SPF checks where the email came from (the server IP)
- DKIM checks what the email contains (the signature)
- DMARC ties them together and enforces the rules
Without SPF, anyone can send from any server using your domain. Without DKIM, your forwarded mail will fail authentication. Without DMARC, failing mail gets delivered anyway — there's no enforcement.
All three are required by Gmail and Yahoo as of 2024, and by Microsoft 365 as of 2025. If you're missing any of them, your email is at risk of being rejected or filtered.
How to check yours
You don't need to dig through DNS yourself. A quick scan of your domain will show you exactly which records exist, whether they're configured correctly, and what's missing.
How does your domain score?
Check your DMARC, SPF, DKIM & MX records in seconds — free, no signup.