Prompt
dkim spf dmarc email api
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you’re looking to send email through an API and want it to land reliably in inboxes, you should set up:
- SPF: authorizes which servers can send for your domain
- DKIM: cryptographically signs outgoing mail
- DMARC: tells receivers how to handle mail that fails SPF/DKIM and gives you reports
What each one does
- SPF: “These IPs/services are allowed to send for my domain.”
- DKIM: “This message really came from me and wasn’t altered.”
- DMARC: “Only accept mail if it passes SPF or DKIM and aligns with my domain.”
Typical setup for an email API
If you use a provider like SendGrid, Mailgun, Amazon SES, Postmark, Brevo, etc.:
- Verify your sending domain in the provider
- Add SPF record they give you to DNS
- Add DKIM CNAME/TXT records they give you to DNS
- Add DMARC record to your DNS
- Test with a few emails and check headers/authentication results
Example DNS records
These are generic examples; your provider will give exact values.
SPF
v=spf1 include:spf.protection.example.com include:sendgrid.net ~all
DKIM
Usually provided as one or more CNAME records, for example:
s1._domainkey.example.com CNAME s1.domainkey.provider.com
s2._domainkey.example.com CNAME s2.domainkey.provider.com
DMARC
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s
Best practice
- Start DMARC with
p=noneto monitor - Move to
quarantine - Then move to
rejectonce everything is aligned - Make sure your From domain matches the authenticated domain as closely as possible
Common reasons email fails
- SPF record has too many lookups
- Multiple SPF records exist
- DKIM not enabled or DNS record missing
- DMARC alignment mismatch
- Sending from a different domain than the one authenticated
If you mean “how do I do this via an API?”
Most email APIs have a domain authentication section where you:
- create a domain
- get DNS records back
- add them in your DNS provider
- verify the domain
- then send mail via the API
If you want, I can give you:
- a step-by-step setup for a specific provider like SendGrid/Mailgun/SES, or
- the exact SPF/DKIM/DMARC records for your domain/provider.