SPF lists who may send email for your domain, DKIM signs each message so it can’t be forged or altered, and DMARC tells receiving servers what to do when a message fails, and sends you a report. With DMARC enforced, the three together stop other people sending email that appears to come from you.
Why it matters now
Two reasons. First, business email compromise, where someone sends email that looks like it came from you or your boss, is where the reported money goes: $3.05 billion in losses reported to the FBI in 2025 alone. Second, the big mailbox providers now expect authentication. Google has required SPF, DKIM and DMARC from anyone sending more than 5,000 messages a day to Gmail addresses since February 2024, and other providers have followed.
SPF: who may send
SPF is a list, published in your domain’s DNS, of the servers allowed to send email for you. A typical one looks like this:
v=spf1 include:spf.protection.outlook.com -all
The ending matters. -all says “reject anything not on the list”, ~all says “treat it with suspicion”. A domain should have exactly one SPF record.
DKIM: a signature on every message
DKIM adds a cryptographic signature to each message. The receiving server checks it against a public key in your DNS, so it can tell the message wasn’t altered and really came from a server you authorized. Your email provider generates the keys; you publish them.
DMARC: the instruction, and the report
DMARC ties the other two together. It tells receiving servers what to do with mail that fails, and asks them to send you reports of who is sending as your domain:
v=DMARC1; p=quarantine; rua=mailto:reports@yourcompany.com
p=none only monitors. p=quarantine sends failures to spam. p=reject refuses them. Only an enforced policy, quarantine or reject, actually stops spoofing.
The path to enforcement
- Publish SPF and turn on DKIM with your email provider.
- Publish DMARC at
p=nonewith a reporting address. - Read the reports for a few weeks. You’ll find senders you forgot: the invoicing system, the newsletter tool, the copier that emails scans.
- Add the legitimate ones to SPF and DKIM.
- Move to
p=quarantine, thenp=reject.
Common mistakes
- Two SPF records. Receiving servers treat that as an error, and SPF fails for everything.
- Too many lookups. SPF allows ten DNS lookups; every
includecounts. Past ten, it fails. +allor?all. They tell servers not to act on failures, so the record protects nothing.- Stopping at
p=none. Monitoring forever is better than nothing, but it doesn’t stop anyone.
Sources: FBI IC3, 2025 Internet Crime Report; Google, new Gmail protections for a safer, less spammy inbox.
Read us first when you search.
GoogleAdd OpsWorq as a preferred source

