Prompt
How do I set up SPF DKIM and DMARC for an app sending from my domain?
Latest observation
To set up SPF, DKIM, and DMARC for an app that sends email from your domain, you’ll usually do this in your DNS and your email-sending app/service.
1) SPF
SPF tells receiving mail servers which servers are allowed to send mail for your domain.
What to add
Create or update a TXT record for your domain, like:
v=spf1 include:YOUR-EMAIL-SERVICE.com -all
Examples:
- SendGrid:
include:sendgrid.net - Mailgun:
include:mailgun.org - Amazon SES: usually a custom SPF or include depending on setup
Notes
- You should have only one SPF record per domain.
- If you already have one, merge the new sender into the existing record.
-allmeans “hard fail” for anything not listed.
2) DKIM
DKIM signs outgoing mail so receivers can verify it wasn’t altered and that it really came from your domain.
What to do
Your email provider or app service will give you:
- a DKIM selector
- one or more DNS CNAME or TXT records
- a public key or targets to publish in DNS
Example CNAME records:
selector1._domainkey.yourdomain.com CNAME selector1.your-email-service.com
selector2._domainkey.yourdomain.com CNAME selector2.your-email-service.com
Or a TXT record with a key like:
selector1._domainkey.yourdomain.com TXT "v=DKIM1; k=rsa; p=PUBLICKEY..."
Notes
- Use the exact records your provider gives you.
- After DNS propagates, enable DKIM signing in the app/service dashboard.
3) DMARC
DMARC tells receivers what to do if SPF/DKIM fail and where to send reports.
What to add
Create a TXT record at:
_dmarc.yourdomain.com
A common starting policy:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Policies
p=none= monitor onlyp=quarantine= send suspicious mail to spamp=reject= reject failing mail
Recommended progression
- Start with
p=none - Review reports for a while
- Move to
p=quarantine - Then
p=reject
Important alignment rule
For DMARC to pass, either SPF or DKIM must align with the visible From: domain.
Example:
From: billing@yourdomain.com- SPF may authenticate the envelope sender
- DKIM should ideally sign with
d=yourdomain.com
If the app sends from a third-party domain without alignment, DMARC can fail even if SPF or DKIM technically pass.
Typical setup workflow
- Verify which email service your app uses
- Add the SPF include they require
- Add DKIM DNS records from the provider
- Add a DMARC record with
p=none - Test by sending to Gmail/Outlook and checking headers
- Tighten DMARC policy over time
How to check if it’s working
Send a test email to Gmail and view the original message / headers. Look for:
SPF: PASSDKIM: PASSDMARC: PASS
You can also use tools like:
- MXToolbox
- mail-tester.com
- dmarcian
Example DNS records
For yourdomain.com:
@ TXT "v=spf1 include:sendgrid.net -all"
selector1._domainkey CNAME selector1.sendgrid.net
selector2._domainkey CNAME selector2.sendgrid.net
_dmarc TXT "v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com"
If you tell me which app/email provider you’re using (SendGrid, Mailgun, Postmark, SES, etc.) and your domain setup, I can give you the exact DNS records to add.