SPF, DKIM and DMARC: Stop Your Emails Landing in Spam
By CodexierPublished 7 min read
If your quotes and invoices land in customers' spam folders, the cause is usually not the content but the missing proof that your domain authorised the message. Three DNS records provide that proof. This guide explains each one without jargon and gives a rollout order that keeps existing mail flowing while you tighten the rules.
Why emails land in spam
The mechanism: email was designed so that anyone can put any address in the 'from' field. Receiving servers therefore look for evidence that the message really came from the domain it claims. Without SPF and DKIM there is no evidence, and the message is scored on content and reputation alone, which is a coin toss for a small domain. With them, the receiver can verify the claim, and your domain builds a reputation of its own.
SPF: who may send
SPF is a single TXT record on your domain that lists the servers allowed to send mail in its name: your mail provider (Microsoft 365 or Google Workspace), your newsletter tool, your invoicing system, your website's form handler. A receiving server checks whether the message came from one of those; if not, SPF fails. Two practical limits matter: there can be only one SPF record, and it may reference at most ten other lookups, which a company with many tools can exceed without noticing.
| Sender | What goes in SPF | Common mistake |
|---|---|---|
| Microsoft 365 or Google Workspace | The provider's include mechanism | Forgetting it after migrating providers |
| Newsletter platform | The platform's include mechanism | Sending from a domain that is not in SPF at all |
| Fortnox or other invoicing | The vendor's documented include, or use their own domain | Invoices failing quietly because the vendor was never added |
| Website forms and notifications | Your host's include, or route them through your mail provider | Web server sending directly with no record |
| Everything else | Ends with a soft or hard fail | Leaving the record open with a neutral ending, which proves nothing |
Count the lookups after every change. Exceeding ten makes SPF fail for everyone, including your own mail provider.
DKIM: signing your mail
DKIM attaches a digital signature to each outgoing message, computed with a private key held by the sending service. The matching public key is published in your DNS, and the receiver uses it to verify that the message was not altered and was sent by a service you authorised. Unlike SPF, DKIM survives forwarding, which is why both are needed. Each service that sends for you needs its own DKIM key: one for your mail provider, one for the newsletter tool, one for the invoicing system.
- Enable DKIM in each service's admin panel; it gives you one or two DNS records to publish.
- Use a key length of 2048 bits where the service offers it.
- Check that the signing domain is your domain, not the vendor's; some tools sign with their own domain by default, which does not help your DMARC alignment.
- Rotate keys when the service recommends it, and remove records for services you stop using.
DMARC: policy and reports
DMARC ties the two together. It is a record that says: for mail claiming to be from this domain, check that SPF or DKIM passes and that the passing identity aligns with the visible from-address, and if not, do this (nothing, quarantine, or reject). It also asks receivers to send you aggregate reports about mail seen in your name, which is how you discover the forgotten senders, and any impostors using your domain in phishing.
p=none
Monitoring only. Nothing is blocked; you receive reports. Start here and stay for a few weeks.
p=quarantine
Failing mail goes to spam. Move here once the reports show all your legitimate senders passing.
p=reject
Failing mail is refused. The goal state: nobody can send as your domain without your keys.
The reports arrive as XML and are unreadable by hand; use a free or low-cost DMARC report viewer, which turns them into a list of sending sources and pass rates. A domain at p=reject is also the strongest single defence against the invoice-fraud emails we describe in our guide to phishing protection for small teams.
Rolling out without breaking mail
- Inventory: list every tool that sends email as your domain. Ask finance, marketing and the website owner; check sent-mail headers if unsure.
- SPF: write one record including every sender, count the lookups, publish, and test with a checker tool.
- DKIM: enable in each service, publish each key, send a test from each and confirm 'dkim=pass' in the received headers.
- DMARC at p=none with a reporting address, and wait two to four weeks while reading the reports.
- Fix every legitimate sender that fails alignment; then move to quarantine, then to reject.
- Document the setup and put a yearly review in the calendar, because tools change and someone will add a new one.
When you do not need help: a company with one mail provider and one newsletter tool can do this in an afternoon with the vendor guides. Buy help when there are many senders, when a previous attempt broke something, or when the domain is already being spoofed; our performance and security optimisation package covers the full rollout to reject, and the monthly maintenance package keeps the records reviewed. Prices are on the pricing page; a short call with your domain name is enough for us to tell you where you stand.
- Performance & Security OptimizationSender inventory, SPF, DKIM for every service and DMARC taken to reject, with the reports set up for you.
- Monthly Maintenance PackageOngoing review of DNS, security and email authentication as tools change.
- Book a free 15-minute callGive us your domain; we check the three records live and tell you what is missing.
Frequently asked questions
We are a small company. Do we really need all three?
Yes, if you send email that matters. Gmail and Microsoft score unauthenticated mail lower for everyone, and the large providers require SPF, DKIM and DMARC from anyone sending in volume. Beyond deliverability, DMARC at reject stops criminals sending invoices in your name, which is a risk regardless of company size.
Will setting this up break our existing email?
Only if a legitimate sender is left out of SPF or DKIM and you move DMARC to quarantine or reject too early. That is why the rollout starts with an inventory and a monitoring-only DMARC policy. Follow the order and read the reports before tightening, and nothing breaks.
How long does it take to see an effect on deliverability?
Authentication takes effect as soon as the DNS records propagate, usually within hours. Reputation builds over weeks of consistent, authenticated sending. If mail was landing in spam for content reasons as well, authentication alone will not fix that, but it removes the biggest single cause.
What are the DMARC reports and who should read them?
Aggregate reports are daily summaries from receiving providers listing every source that sent mail as your domain and whether it passed. They are XML files, so use a report viewer. Whoever owns your DNS or IT should glance at them weekly during rollout and monthly afterwards; new sources appearing in the reports are either a colleague's new tool or an impostor.
Want to know if your domain passes?
Bring your domain name to a fifteen-minute call. We check SPF, DKIM and DMARC live, explain what each result means for your invoices and quotes, and say what a full rollout would cost.
Book a free 15-minute call