Guide · email

SPF, DKIM, and DMARC explained for small businesses.

Do your emails land in spam, or is someone sending email that looks like it comes from your domain? Here is what these three protections do, how to check them, and the order to set them up without cutting off your legitimate mail.

Why your emails land in spam

Email providers (Gmail, Outlook, Yahoo) check whether a message is really allowed to be sent in the name of your domain. Without a clear answer, the message is treated as suspicious. Three DNS records provide that answer: SPF, DKIM, and DMARC.

The three protections, one sentence each

  • SPF lists the servers allowed to send email for your domain.
  • DKIM adds a digital signature to every message; the recipient checks it against a key published in your DNS.
  • DMARC says what to do when SPF and DKIM fail (nothing, quarantine, or reject) and where to send the reports.

For DMARC to pass, the domain visible in the “From” address must match the domain validated by SPF or DKIM. This is called alignment.

What the records look like

Examples for Microsoft 365 and Google Workspace. Your services may differ: always check your provider’s documentation.

SPF, Microsoft 365 (TXT on your domain)
v=spf1 include:spf.protection.outlook.com -all

SPF, Google Workspace (TXT on your domain)
v=spf1 include:_spf.google.com ~all

DMARC (TXT on _dmarc.yourdomain.com)
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

For DKIM, Microsoft 365 publishes two CNAME records (selector1._domainkey and selector2._domainkey) and Google Workspace publishes one TXT record (google._domainkey). Your provider gives you the exact values.

How to check your domain

  1. Send a message from your business address to a personal Gmail address, open it, then choose “Show original”: Gmail shows PASS or FAIL for SPF, DKIM, and DMARC.
  2. Look up your records with a DNS lookup tool, or with the command nslookup -type=txt yourdomain.com (SPF). For DMARC, query _dmarc.yourdomain.com; for DKIM, query your provider’s selector (selector1._domainkey.yourdomain.com or google._domainkey.yourdomain.com).
  3. Check that there is only one SPF record. Two SPF records make the check fail.

The most common mistakes

  • A second SPF record added by another provider, instead of one combined record.
  • Too many services in the SPF record: the standard limits it to 10 DNS lookups.
  • A service that sends in your name (newsletter, invoicing, CRM) but is neither in the SPF record nor signed with DKIM.
  • DMARC left at p=none forever: it monitors, but does not protect.
  • Jumping straight to p=reject without reading the reports: legitimate email can get blocked.

A safe order for setting up DMARC

  1. List every service that sends email with your domain (Microsoft 365 or Google, newsletter, invoicing, website forms).
  2. Publish a single SPF record that covers them, and turn on DKIM for each.
  3. Publish DMARC with p=none and an address for reports (rua), then read the reports for a few weeks.
  4. Fix what fails, move to p=quarantine, then to p=reject once everything is in order.

What changes with Gmail, Yahoo, and Microsoft

Since February 2024, Gmail and Yahoo require SPF, DKIM, and DMARC from senders of large volumes (Google sets the threshold at more than 5,000 messages a day to Gmail; Yahoo does not publish one). Microsoft has applied similar requirements to Outlook.com, Hotmail.com, and Live.com since May 5, 2025 (5,000 messages a day or more); non-compliant messages can be rejected. Even at small volumes, these records help your email arrive.

Need a hand?

Is your email not arriving?

Describe your situation and the email service you use. I will tell you how I can help.