Skip to content
FlexibleToolsAI
Security Guide9 min read Updated September 28, 2026

How to Check and Set Up SPF, DKIM and DMARC

SPF, DKIM and DMARC are three DNS records that stop criminals sending email that pretends to come from your domain — and since 2024, Gmail and Yahoo require them for bulk senders. Here's what each one does, how to check yours in a minute, and how to set them up step by step.

Quick Takeaway

To check them, look up your domain's TXT records: SPF is a v=spf1 record on the domain, DKIM is at selector._domainkey.yourdomain, and DMARC is at _dmarc.yourdomain. Free checkers do this instantly and flag errors like two SPF records, more than 10 DNS lookups, or a DMARC policy stuck at p=none. To set them up, publish one SPF record listing your mail providers, turn on DKIM signing in each provider, then add DMARC starting at p=none and move to quarantine and reject.

SPF, DKIM and DMARC in one minute

SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message, proving it wasn't altered and came from an authorised sender. DMARC ties the two to the From address people actually see, tells receivers what to do with mail that fails (nothing, spam folder, or reject) and sends you reports.

You need all three: SPF alone breaks when mail is forwarded, DKIM alone doesn't stop someone using your domain in the From line, and DMARC does nothing without SPF or DKIM to check.

How to check SPF, DKIM and DMARC for a domain

The quickest way is a free online checker: the Domain Security Checker scans SPF, DMARC and DNSSEC in one go, and the SPF Record Checker, DKIM Record Checker and DMARC Record Checker explain every tag and error.

From a terminal you can query the records directly: dig TXT example.com (SPF), dig TXT _dmarc.example.com (DMARC), and dig TXT google._domainkey.example.com (DKIM, replacing google with your selector). On Windows use nslookup -type=TXT _dmarc.example.com.

To check whether a specific email passed, open it and view the original message (Gmail: ⋮ → Show original). Look for spf=pass, dkim=pass and dmarc=pass in the Authentication-Results header.

How to set up SPF

Publish exactly one TXT record on your root domain that lists every service that sends mail as you, ending in ~all. For Google Workspace alone it's v=spf1 include:_spf.google.com ~all; for Microsoft 365 it's v=spf1 include:spf.protection.outlook.com ~all. Add an include for each extra sender (newsletter, CRM, helpdesk) in the same record.

Stay under 10 DNS lookups — every include, a, mx and redirect counts, including the ones inside your providers' records. Exceeding it makes SPF fail for all your mail. The SPF checker counts them for you.

How to set up DKIM

DKIM is switched on in each sending service, which gives you a DNS record to publish. In Google Workspace: Admin console → Apps → Gmail → Authenticate email → Generate new record, add the TXT record at google._domainkey, then click Start authentication. In Microsoft 365: Defender portal → Email authentication settings → DKIM, publish the two CNAME records (selector1 and selector2), then enable signing.

Use 2048-bit keys where offered, and repeat for every service that sends mail as your domain (Mailchimp, SendGrid, your CRM…).

How to set up DMARC safely

Add a TXT record at _dmarc.yourdomain: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain. p=none changes nothing about delivery but starts daily reports showing every service sending as your domain.

After a few weeks, once your legitimate senders pass SPF or DKIM, change to p=quarantine (failures go to spam), then p=reject (failures are refused). Domains that never send email should publish v=spf1 -all and v=DMARC1; p=reject so they can't be spoofed at all.

Common mistakes

Two SPF records instead of one merged record. Forgetting a sending service, so its mail fails once DMARC is enforced. Leaving DMARC at p=none forever. Using ?all or +all in SPF. Publishing DKIM but never clicking “start signing” in the provider. Re-check after every change with the Domain Security Checker.

Try Free Web Tools Mentioned in This Guide

Frequently Asked Questions

What's the difference between SPF, DKIM and DMARC?↓

SPF lists allowed sending servers, DKIM signs messages so they can't be altered, and DMARC checks that one of them matches the visible From address and tells receivers what to do when they don't.

Do I need DMARC if I have SPF and DKIM?↓

Yes. Without DMARC, receivers decide on their own what to do with failures, anyone can still spoof your From address, and you get no reports. Gmail and Yahoo require DMARC for bulk senders.

How long does it take for DNS changes to work?↓

Usually minutes, sometimes up to a few hours depending on the record's TTL. Re-check with an online checker to confirm.

Why do my emails go to spam even with SPF and DKIM?↓

Authentication is only one signal. Check DMARC alignment (the From domain must match the SPF or DKIM domain), your sending reputation, and the content and volume of your mail.

Related Guides