Email authentication
SPF, DKIM, and DMARC explained for business owners.
These three DNS-based controls help receiving mail systems decide whether a message really came from your business. They are related, but they do different jobs.
Updated September 2026 · Cyber Bounds Inc.
Why this matters now
Major mailbox providers expect authenticated mail. Gmail’s current sender guidance requires all senders to use SPF or DKIM, while bulk senders need SPF, DKIM, and DMARC; it also requires alignment between the visible From domain and an authenticating domain for direct mail. That means simply publishing records is not enough—your actual mail needs to use them correctly.
SPF: who is allowed to send
SPF is a public DNS record that lists systems permitted to send mail for a domain. Your Google Workspace or Microsoft 365 tenant may be one authorized sender, but so might your website forms, invoicing platform, CRM, booking software, help desk, or marketing platform.
SPF problems often appear after a business adds a new tool and the tool starts sending with the main company domain. It may work for some recipients but fail checks elsewhere. SPF also has a lookup limit, which is why records should be designed rather than continually appended.
DKIM: proof the message was signed
DKIM adds a cryptographic signature to a message. The receiving server looks up a public key in DNS and verifies that the message was signed by an approved domain and was not altered after signing. Unlike SPF, DKIM tends to survive normal forwarding more reliably.
Turn on DKIM in every email platform that supports it, then verify a real message header. A key existing in DNS does not prove that your important messages are using it.
DMARC: the rule that connects identity and policy
DMARC checks whether SPF or DKIM passed in a way that aligns with the domain visible in the From address. It also tells receivers how to handle mail that fails and can send aggregate reports about who is using your domain.
Many businesses start with a monitoring policy while they discover legitimate senders. Moving to quarantine or reject should happen only after reviewing the sources in those reports. A strict policy applied too early can interrupt valid mail.
A safe order of operations
- List every system that sends as your business.
- Confirm SPF and DKIM for each legitimate sender.
- Check message headers from real sends, not just DNS scanners.
- Publish or review DMARC reporting.
- Move toward enforcement only after the sending map is complete.
When to ask for help
Bring in specialist help if the domain is business-critical, multiple vendors send email for you, a platform migration is underway, or you are seeing spoofing and spam-placement symptoms at the same time. An email deliverability engagement can map the complete sender environment and create a safer remediation sequence.