Site AI Auditby Internet Solutions

SPF vs DKIM vs DMARC: What Each One Does and Why You Need All

৫ আগস্ট, ২০২৬8 মিনিটে পড়াই-মেইল ডেলিভারেবিলিটি
SPF vs DKIM vs DMARC: What Each One Does and Why You Need All

Short answer: SPF lists the servers allowed to send mail for your domain, DKIM signs each message so receivers can verify it was not altered, and DMARC checks that at least one of them passes for the same domain shown in the From address, then tells receivers what to do if it does not. They are not alternatives. Mailbox providers expect all three, and each one covers a weakness of the others.

Why one check is not enough

E-mail has several “sender” fields, and that is the root of the confusion. There is the envelope sender, which servers use for bounces and which the recipient never sees. There is the signing domain in the DKIM signature, which is also hidden. And there is the From header, the address and name that appear in the inbox. Criminals exploit the gaps between these fields.

Each standard looks at a different field:

Only DMARC looks at what the human sees. Only SPF and DKIM actually prove anything cryptographically or by IP address. That is why they work as a set.

SPF in one minute

SPF is a single TXT record at the root of your domain that lists approved senders, usually through include: statements for your mail provider and tools, and ends with ~all or -all. The receiving server compares the connecting IP address with the list.

Strengths: simple, one record, widely supported, and easy to check from outside.

Weaknesses: breaks when mail is forwarded, is limited to ten DNS lookups, and says nothing about the visible From address. A domain with many tools can struggle to fit everything into one record.

DKIM in one minute

DKIM uses a pair of keys. The sending service keeps a private key and signs each message; you publish the public key in DNS under a selector such as selector1._domainkey.yourdomain.com. The receiving server verifies the signature against that key.

Strengths: survives most forwarding, proves the content was not altered, supports many senders with separate keys, and builds reputation for your domain.

Weaknesses: must be set up separately in every sending service, can break when intermediaries modify the message, and many services sign with their own domain unless you configure yours.

DMARC in one minute

DMARC is a TXT record at _dmarc.yourdomain.com with a policy (none, quarantine or reject) and an address for reports. A message passes if SPF or DKIM passes and the passing domain aligns with the From domain.

Strengths: protects the visible address, lets you instruct receivers to reject spoofed mail, and gives you reports about everyone sending with your domain.

Weaknesses: depends entirely on SPF and DKIM being right, needs a careful rollout, and does not stop lookalike domains.

Side-by-side comparison

SPFDKIMDMARC
Question it answersIs this server allowed?Is the signature valid?Does a pass match the From domain?
Where it lives in DNSTXT at the root domainTXT or CNAME at selector._domainkeyTXT at _dmarc
Records per domainExactly oneOne per selector, many allowedExactly one
Survives forwardingUsually notUsually yesIf DKIM survives
Protects the visible FromNoNoYes
Gives you reportsNoNoYes
Typical failure causeMissing sender, too many lookupsSigning not enabled, wrong DNS nameThird-party tools not aligned

How the three work together on one message

Imagine an invoice sent from your accounting software with the From address [email protected].

  1. The accounting tool connects to the recipient’s server and uses its own bounce address, [email protected]. SPF passes, but for the vendor’s domain.
  2. The message carries a DKIM signature. If you set up custom domain authentication in the tool, the signature says d=yourdomain.com and passes.
  3. DMARC compares: SPF passed for the vendor’s domain, which does not align. DKIM passed for yourdomain.com, which does. One aligned pass is enough, so DMARC passes.

Now imagine you skipped the DKIM setup in that tool. SPF still passes for the vendor, DKIM passes for the vendor, and DMARC fails, because neither pass belongs to your domain. With p=none nothing visible happens, but with p=reject your invoices bounce. This is the single most common surprise when businesses enforce DMARC, and it is why the rollout starts with reports.

Now imagine a criminal sending a fake invoice from their own server with your From address. SPF fails or passes only for their domain, and they cannot produce a DKIM signature for your domain without your private key. DMARC fails, and with an enforcing policy the message is quarantined or rejected.

The order to set them up

  1. SPF first for your main mail provider, because it is one record and often part of the provider’s setup wizard.
  2. DKIM next in the mail provider, then in every other service that sends with your domain: newsletter, CRM, helpdesk, shop, invoicing.
  3. DMARC with p=none and a report address, as soon as the main provider passes SPF and DKIM.
  4. Use the reports to find and fix remaining senders over a few weeks.
  5. Enforce with p=quarantine, then p=reject.

You can publish DMARC before everything is perfect. With p=none it changes nothing about delivery, and the reports are the best way to discover what still needs fixing.

A few practical tips make the process smoother:

What mailbox providers expect today

Since 2024, Google and Yahoo have required everyone sending to their users to have SPF or DKIM, and bulk senders to have both, plus a DMARC record and alignment of the From domain with SPF or DKIM. Microsoft announced similar requirements for high-volume senders to Outlook.com. Rules and thresholds can change, so check the providers’ own sender guidelines, such as Google’s e-mail sender guidelines, when you plan larger campaigns.

Even if you send only a handful of messages a day, the same standards decide whether your quotes and replies reach customers. Small senders simply have less room for error, because they have less sending history for filters to rely on.

It also helps to remember that authentication is a precondition, not a guarantee. Once SPF, DKIM and DMARC are right, filters move on to other questions: do recipients open and reply to your mail, do they mark it as spam, do your messages bounce because the list is old? Authentication makes your good behaviour count for your own domain. Without it, even a well-run mailing list starts every message at a disadvantage, and anyone can borrow your name to send something harmful.

Checking all three at once

Looking at a real message header is the most direct test: the Authentication-Results line shows spf=, dkim= and dmarc= results together. To see the published records from outside, Site AI Audit checks SPF (including its lookup limit), DKIM, DMARC and MX records in one pass, next to the website’s SEO, speed and SSL, and ranks the findings by impact. A free check shows where your domain stands, and paid plans on the pricing page repeat the checks and alert you when a record breaks.

Related reading

The bottom line

SPF approves servers, DKIM signs messages and DMARC ties both to the address people see while giving you a policy and reports. Set them up in that order, make sure every tool that sends with your domain is aligned, and then enforce DMARC. Having only one or two of the three leaves a gap that both spam filters and criminals notice.

FAQ

Can I use DKIM without SPF?

Technically DKIM alone can pass DMARC, but mailbox providers expect both, and bulk sender rules require both. SPF is also a quick signal for receivers that do not evaluate DKIM in every case, so publish both.

Which is most important: SPF, DKIM or DMARC?

They do different jobs, so none replaces another. If you must prioritise, get SPF and DKIM working for your main provider, then add DMARC with p=none immediately so you can see what else sends mail as you.

Does DMARC replace SPF and DKIM?

No. DMARC has no check of its own; it evaluates the SPF and DKIM results and adds alignment, policy and reporting. Without working SPF or DKIM, every message fails DMARC.

Why does my message pass SPF and DKIM but fail DMARC?

Because the passes belong to a different domain than your From address, typically the domain of a newsletter or CRM platform. Set up custom domain authentication in that service so it signs with your domain.

Do I need all three for a small business domain?

Yes. The records are free, take little time to publish and protect both your deliverability and your customers from invoice fraud using your name. Small domains benefit because they have less sending history to fall back on.

#DKIM#DMARC#Email Authentication#SPF
নিজের ওয়েবসাইট চেক করুন — ফ্রি।আপনার ওয়েবসাইটে কী ঠিক করতে হবে — আর কোথা থেকে শুরু করবেন।
বিনামূল্যে শুরু

ব্লগ থেকে আরও

সব আর্টিকেল →
Internet Solutions

আমাদের টিমের আরও কিছু

Internet Solutions-এর তৈরি। আমাদের অন্য প্রোডাক্টগুলোও ব্যবহার করে দেখুন — প্রতিটি আলাদা ভাবে আপনার সময় বাঁচায়।

internet-solutions.net ↗
01সোশ্যাল মিডিয়ায় অটো-পোস্টিং
PostRSS

আপনার RSS ফিডের নতুন পোস্ট স্বয়ংক্রিয়ভাবে Facebook, X, LinkedIn, Telegram এবং আরও ৬০+ নেটওয়ার্কে চলে যায়।

ফ্রি প্ল্যান · ২০১৪ থেকেদেখুন →
02ওয়েবসাইটের জন্য AI লাইভ চ্যাট
Talkmio

আপনার ওয়েবসাইট আপনার নিজের কনটেন্ট থেকে, ভিজিটরের ভাষায়, ২৪/৭ উত্তর দেয়।

ফ্রি প্ল্যান · কার্ড লাগবে নাদেখুন →
03AI সহকারী
Ask Mio

চ্যাট, কোড, ডিজাইন, লেখা ও গবেষণা। প্রতিটি কাজের জন্য Mio সেরা মডেল বেছে নেয়।

ফ্রি প্ল্যানদেখুন →
04ব্লগ ও সোশ্যাল মিডিয়ার জন্য AI অটোপাইলট
AI Blog Autopilot

AI ২,০০০–৩,০০০ শব্দের SEO আর্টিকেল লেখে এবং প্রতিটি ৫৮+ সোশ্যাল নেটওয়ার্কে শেয়ার করে।

প্রথম ৩টি আর্টিকেল ফ্রিদেখুন →
05গভীর SEO ক্রল
Site SEO AI Audit

AI সার্চে দৃশ্যমানতাসহ ৭টি ক্ষেত্রে পূর্ণ SEO ক্রল, প্রভাব অনুযায়ী সাজানো সমাধানসহ।

প্রথম অডিট ফ্রিদেখুন →
06RSS ও প্রোডাক্ট ফিড
RSS Feed Creator

যেকোনো ওয়েব পেজ থেকে RSS তৈরি করুন, সঙ্গে Google ও Meta-র জন্য নিজে থেকে আপডেট হওয়া প্রোডাক্ট ফিড।

ফ্রি প্ল্যানদেখুন →
07ওয়েব ডেভেলপমেন্ট ও SEO
Internet Solutions

ওয়েবসাইট, ই-শপ ও কাস্টম সিস্টেম — আমাদের টিম ডিজাইন করে, তৈরি করে এবং চালায়।

২০১১ থেকেদেখুন →
Site AI Audit
গোপনীয়তার সারসংক্ষেপ

এই ওয়েবসাইট কুকি ব্যবহার করে যাতে আমরা আপনাকে সর্বোত্তম ব্যবহারকারী অভিজ্ঞতা দিতে পারি। কুকির তথ্য আপনার ব্রাউজারে সংরক্ষিত থাকে এবং এমন কাজ করে যেমন আপনি ফিরে এলে আপনাকে চিনতে পারা এবং ওয়েবসাইটের কোন অংশ আপনার কাছে সবচেয়ে আকর্ষণীয় ও উপযোগী তা আমাদের টিমকে বুঝতে সাহায্য করা।