Prompt

dkim spf dmarc email api

Technology / Developer Tools1 observationLast seen Oct 6, 2026

Latest observation

Oct 6, 2026OpenAI APIWeb search: off

If you’re looking to send email through an API and want it to land reliably in inboxes, you should set up:

  • SPF: authorizes which servers can send for your domain
  • DKIM: cryptographically signs outgoing mail
  • DMARC: tells receivers how to handle mail that fails SPF/DKIM and gives you reports

What each one does

  • SPF: “These IPs/services are allowed to send for my domain.”
  • DKIM: “This message really came from me and wasn’t altered.”
  • DMARC: “Only accept mail if it passes SPF or DKIM and aligns with my domain.”

Typical setup for an email API

If you use a provider like SendGrid, Mailgun, Amazon SES, Postmark, Brevo, etc.:

  1. Verify your sending domain in the provider
  2. Add SPF record they give you to DNS
  3. Add DKIM CNAME/TXT records they give you to DNS
  4. Add DMARC record to your DNS
  5. Test with a few emails and check headers/authentication results

Example DNS records

These are generic examples; your provider will give exact values.

SPF

v=spf1 include:spf.protection.example.com include:sendgrid.net ~all

DKIM Usually provided as one or more CNAME records, for example:

s1._domainkey.example.com CNAME s1.domainkey.provider.com
s2._domainkey.example.com CNAME s2.domainkey.provider.com

DMARC

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s

Best practice

  • Start DMARC with p=none to monitor
  • Move to quarantine
  • Then move to reject once everything is aligned
  • Make sure your From domain matches the authenticated domain as closely as possible

Common reasons email fails

  • SPF record has too many lookups
  • Multiple SPF records exist
  • DKIM not enabled or DNS record missing
  • DMARC alignment mismatch
  • Sending from a different domain than the one authenticated

If you mean “how do I do this via an API?”

Most email APIs have a domain authentication section where you:

  • create a domain
  • get DNS records back
  • add them in your DNS provider
  • verify the domain
  • then send mail via the API

If you want, I can give you:

  1. a step-by-step setup for a specific provider like SendGrid/Mailgun/SES, or
  2. the exact SPF/DKIM/DMARC records for your domain/provider.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.