OPSWORQ

Guide

SPF, DKIM and DMARC in plain English

By OpsWorq engineeringReviewed September 20266 min read

SPF lists who may send email for your domain, DKIM signs each message so it can’t be forged or altered, and DMARC tells receiving servers what to do when a message fails, and sends you a report. With DMARC enforced, the three together stop other people sending email that appears to come from you.

Why it matters now

Two reasons. First, business email compromise, where someone sends email that looks like it came from you or your boss, is where the reported money goes: $3.05 billion in losses reported to the FBI in 2025 alone. Second, the big mailbox providers now expect authentication. Google has required SPF, DKIM and DMARC from anyone sending more than 5,000 messages a day to Gmail addresses since February 2024, and other providers have followed.

SPF: who may send

SPF is a list, published in your domain’s DNS, of the servers allowed to send email for you. A typical one looks like this:

v=spf1 include:spf.protection.outlook.com -all

The ending matters. -all says “reject anything not on the list”, ~all says “treat it with suspicion”. A domain should have exactly one SPF record.

DKIM: a signature on every message

DKIM adds a cryptographic signature to each message. The receiving server checks it against a public key in your DNS, so it can tell the message wasn’t altered and really came from a server you authorized. Your email provider generates the keys; you publish them.

DMARC: the instruction, and the report

DMARC ties the other two together. It tells receiving servers what to do with mail that fails, and asks them to send you reports of who is sending as your domain:

v=DMARC1; p=quarantine; rua=mailto:reports@yourcompany.com

p=none only monitors. p=quarantine sends failures to spam. p=reject refuses them. Only an enforced policy, quarantine or reject, actually stops spoofing.

The path to enforcement

  1. Publish SPF and turn on DKIM with your email provider.
  2. Publish DMARC at p=none with a reporting address.
  3. Read the reports for a few weeks. You’ll find senders you forgot: the invoicing system, the newsletter tool, the copier that emails scans.
  4. Add the legitimate ones to SPF and DKIM.
  5. Move to p=quarantine, then p=reject.

Common mistakes

  • Two SPF records. Receiving servers treat that as an error, and SPF fails for everything.
  • Too many lookups. SPF allows ten DNS lookups; every include counts. Past ten, it fails.
  • +all or ?all. They tell servers not to act on failures, so the record protects nothing.
  • Stopping at p=none. Monitoring forever is better than nothing, but it doesn’t stop anyone.

Sources: FBI IC3, 2025 Internet Crime Report; Google, new Gmail protections for a safer, less spammy inbox.

Read us first when you search.

GoogleAdd OpsWorq as a preferred source

Get started

Questions this guide didn’t answer?

1‑855‑OPSWORQ

855‑677‑9677 · Mon–Fri, 8am–5pm ET

If the business has stopped, call. Don’t use the form.

Ask the engineers who wrote it. A person replies within one business day.

What’s it about? Select all that apply.

A sentence is plenty.

A person replies within one business day. Nothing is sold, and you’re not added to a mailing list.

Prefer to talk? Pick a time for a 20‑minute review Or call 1‑855‑OPSWORQ.

Call Get your price