Prompt
SPF DKIM DMARC setup for sending domain
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
Here’s a practical setup guide for SPF, DKIM, and DMARC for a sending domain.
1) SPF
Purpose: tells receivers which servers are allowed to send mail for your domain.
Example SPF record
If you only send from your mail provider:
example.com TXT "v=spf1 include:_spf.google.com ~all"
If you send from multiple services, combine them:
example.com TXT "v=spf1 include:_spf.google.com include:sendgrid.net include:mailgun.org -all"
Notes
- Use one SPF record only per domain.
- Keep DNS lookups under 10.
- Start with
~all(softfail) while testing, then move to-allwhen confident.
2) DKIM
Purpose: adds a cryptographic signature to outgoing mail so recipients can verify it wasn’t altered and is authorized.
Setup steps
- Generate a DKIM key pair in your email provider or mail server.
- Publish the public key in DNS as a TXT record.
- Configure your mail system/provider to sign outgoing email with the private key.
Example DKIM DNS record
selector1._domainkey.example.com TXT "v=DKIM1; k=rsa; p=PUBLIC_KEY_HERE"
Notes
- Use a strong key length, ideally 2048-bit if supported.
- You can have multiple selectors (useful for rotation).
3) DMARC
Purpose: tells receivers what to do if SPF/DKIM fail and provides reporting.
Example DMARC record
Start in monitoring mode:
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s"
Then later enforce:
_dmarc.example.com TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s"
Finally:
_dmarc.example.com TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s"
Notes
rua= aggregate reports.- Start with
p=none, review reports, then move toquarantineorreject. - Alignment matters:
aspf=s= strict SPF alignmentadkim=s= strict DKIM alignment
Recommended rollout
- Publish SPF
- Enable DKIM signing
- Add DMARC with
p=none - Monitor reports for 1–2 weeks
- Fix any unauthorized sources or misconfigurations
- Tighten DMARC to
quarantine, thenreject
Common pitfalls
- Having multiple SPF records
- Exceeding SPF’s 10 DNS lookup limit
- DKIM key not matching selector/name in DNS
- DMARC failing because the visible
From:domain doesn’t align with SPF/DKIM - Third-party senders not added to SPF or not DKIM-signed
If you want, I can generate the exact DNS records for your domain based on:
- your domain name
- your email provider(s) (Google Workspace, Microsoft 365, SendGrid, Mailgun, SES, etc.)
- whether you send from a website/app/server