Email was built without any proof of who sent a message. Anyone can write “From: billing@yourcompany.com” on an email. Three DNS records let receiving mail servers tell the real thing from a fake: SPF, DKIM and DMARC. Without them, a fake invoice “from you” can land in your customer’s inbox looking perfectly normal.
SPF: who may send for you
SPF is a single TXT record on your domain that lists the services allowed to send your mail. If you use Google Workspace:
v=spf1 include:_spf.google.com ~all
Add an include: for each service that sends as you: your email host, your newsletter tool, your transactional email provider. Two things trip people up. You may have only one SPF record, so merge them rather than adding a second. And SPF allows at most 10 DNS lookups; each include counts, and going over makes the record fail.
DKIM: a signature on every message
DKIM adds a cryptographic signature to each email. The receiving server checks it against a public key you publish in DNS, at an address like selector._domainkey.yourcompany.com. You don’t write this record yourself: each sending service gives it to you in its dashboard under “domain authentication”. Set it up for every service that sends as your domain.
DMARC: what to do with fakes
DMARC ties the two together. It tells receiving servers what to do when a message claiming to be from you fails SPF and DKIM, and where to send reports about it. It’s a TXT record at _dmarc.yourcompany.com. Start by only watching:
v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com
Read the reports for a couple of weeks. They show every service sending as you, including ones you forgot. Once all your real mail passes, tighten the policy to p=quarantine (fakes go to spam) and then p=reject (fakes are refused). p=none is a starting point, not protection.
Check yours
- Look up your records from a terminal:
Or use any free online DNS lookup tool.dig TXT yourcompany.com +short dig TXT _dmarc.yourcompany.com +short - Send an email from each service you use to a Gmail address, open it, and choose Show original. You want SPF, DKIM and DMARC all marked PASS.
- If you don’t send email from a domain at all, lock it down completely with
v=spf1 -allandp=reject, so nobody can use it.
It’s not only about fakes. Since 2024, Google and Yahoo require bulk senders to have SPF, DKIM and DMARC in place, so getting this right also helps your real email reach the inbox.
p=reject.