Prompt
How do I set up SPF DKIM and DMARC for my sending domain?
Latest observation
To set up SPF, DKIM, and DMARC for your sending domain, you need to publish the right DNS records and make sure your mail system or email provider signs outgoing mail correctly.
1) SPF
SPF tells receiving servers which servers are allowed to send mail for your domain.
What to add
Create a TXT record for your domain:
v=spf1 include:your-email-provider.com -all
Example
If you send through Google Workspace:
v=spf1 include:_spf.google.com -all
If you send through Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all
Notes
- You should have only one SPF record per domain.
- Keep it under the SPF lookup limit: 10 DNS lookups max.
-allmeans only listed servers are authorized.- If you are still testing, some people use
~allfirst, then switch to-all.
2) DKIM
DKIM adds a cryptographic signature to outgoing emails so recipients can verify the message was not altered and truly came from your domain.
What to do
Your email provider or mail server will generate:
- a DKIM selector
- a public key
- a TXT DNS record
The record usually looks like this:
Host/Name
selector1._domainkey.yourdomain.com
Value
v=DKIM1; k=rsa; p=PUBLIC_KEY_HERE
Important
- Enable DKIM signing in your sending system.
- Publish the DKIM public key in DNS.
- Use a 2048-bit key if possible.
3) DMARC
DMARC tells receiving servers what to do if SPF and/or DKIM fail, and it also provides reporting.
What to add
Create a TXT record at:
_dmarc.yourdomain.com
Starter policy
Begin with monitoring only:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Then move to stronger policies:
p=quarantine— suspicious mail goes to spamp=reject— failing mail is rejected
Example stricter policy:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com
Or:
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com
Optional tags
pct=50— apply policy to 50% of mailaspf=s— strict SPF alignmentadkim=s— strict DKIM alignment
Recommended setup order
- Set up your mail provider/send server
- Publish SPF
- Enable and publish DKIM
- Publish DMARC with
p=none - Review DMARC reports
- Move to
quarantine, thenreject
Best-practice example
For a domain example.com, your DNS might include:
SPF
example.com. TXT "v=spf1 include:_spf.google.com -all"
DKIM
selector1._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
DMARC
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
Common mistakes
- Multiple SPF records
- Forgetting to enable DKIM signing in the sending platform
- DMARC set to
rejectbefore SPF/DKIM are working - Misaligned “From” domain and sending domain
- Exceeding SPF DNS lookup limits
- Using a weak DKIM key length
If you tell me which provider you send through (Google Workspace, Microsoft 365, SendGrid, Amazon SES, Mailchimp, a custom SMTP server, etc.) and your domain registrar/DNS host, I can give you the exact records to add.