Plain-English guide

SPF, DKIM & DMARC — explained simply

Three email-security checks with intimidating names. Here's what each one actually does, why your business needs all three, and how to tell if yours are working — no jargon, no acronym soup.

5-minute read Updated July 2026 Written for non-technical teams

What is email authentication?

Here's the uncomfortable truth email was built on: by default, anyone can put your company's name on an email — the same way anyone can scribble your address on the back of an envelope. Nothing in the original design stops a stranger from sending a fake invoice that looks like it came from you.

Email authentication fixes that. It's a set of three checks that let the big inbox providers — Gmail, Outlook, Yahoo — confirm a message really came from you, and quietly bin the ones that didn't. The three checks are SPF, DKIM and DMARC, and they work as a team:

  • SPF proves the message came from a server you approve.
  • DKIM proves the message wasn't tampered with on the way.
  • DMARC ties the two together, sets the rule for fakes, and reports who's sending as you.

You need all three. SPF and DKIM each cover one angle; DMARC is the one that actually stops impersonation and lets you see it happening.

SPF The approved-senders list

SPF (Sender Policy Framework) is a public list of the servers allowed to send email for your domain — think of it as the guest list at the door. When a message arrives claiming to be from you, the receiving inbox asks one question: "Was this sent from a server on the list?" If yes, it looks legitimate. If not, it's treated as suspicious.

Server on your list
SPF
Delivered
Server not listed
SPF
Spam / rejected
Real mail comes from a server on your list and passes; a stranger's server isn't listed and fails.
What an SPF record looks like
v=spf1 include:_spf.google.com include:sendgrid.net ~all

The catch: add a new tool — a newsletter platform, an invoicing app, a booking system — and forget to add it to this list, and your real mail starts failing and landing in spam. That's why SPF isn't "set and forget"; it needs watching.

DKIM The tamper-proof seal

DKIM (DomainKeys Identified Mail) adds an invisible, un-forgeable wax seal to every email you send. The receiving inbox checks the seal: if it's intact, the message genuinely came from you and nothing was changed in transit. If the seal is missing or broken, the message can't be trusted.

Sealed by you
DKIM
Trusted
No seal / altered
DKIM
Not trusted
An intact cryptographic seal proves the message is yours and unmodified; a broken or missing seal fails.

Because the seal is cryptographic, an impersonator can't fake it — they don't have your private key. DKIM also survives some forwarding that SPF doesn't, which is why you want both.

DMARC The rulebook & your CCTV

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the one that pulls it all together. It does two powerful things:

  • Sets the rule. A message must pass SPF or DKIM and the name must match your visible "From" address. Then you decide what happens to anything that fails.
  • Turns on the CCTV. DMARC quietly emails you daily reports of everyone sending mail as you — the good and the fake. This is how you finally see impersonation.
Passes & matches
DMARC
Inbox
Impersonator
DMARC
Blocked
…and a daily report of it all lands with you
DMARC decides the fate of every message by your rule — and reports the whole picture back to you.

You choose how strict the rule is, and you tighten it over time as you gain confidence:

p=noneJust watch — nothing is blocked yet
p=quarantineSend fakes to the spam folder
p=rejectBlock fakes outright — full protection
What a DMARC record looks like
v=DMARC1; p=reject; rua=mailto:reports@yourdomain.co.uk

Gmail & Yahoo now require this

Since February 2024, Gmail and Yahoo require a valid DMARC record for anyone sending email in volume. No DMARC no longer just means "less secure" — it means your legitimate mail is likelier to be filtered to spam or rejected outright. Email authentication has gone from best-practice to mandatory.

How MailSurety does this for you

The records above are only a few lines of DNS — but getting all three right, and keeping them right every time you add a new tool, is exactly where most businesses trip up. One wrong character and your real invoices go to spam; one gap and someone's forging your name without you knowing.

That's the whole job MailSurety does:

  • We set up SPF, DKIM and DMARC with you — or check what you already have.
  • We read your DMARC reports every day, so you never have to open one.
  • We tell you in plain English what's fine and what to fix — "this is your newsletter, that's a fake, block it."
  • We guide you safely from watching to blocking, without losing a single real email.

See where your domain stands — free

Instant score of your live SPF, DKIM & DMARC setup. No signup, nothing stored.

Check my domain

Common questions

Do I need all three of SPF, DKIM and DMARC?

Yes. SPF and DKIM are two independent ways to prove a message is really from you; DMARC ties them together, tells inboxes what to do with fakes, and reports who's sending as you. DMARC in particular is what actually stops impersonation and gives you visibility.

What happens if I don't have DMARC?

Anyone can send email that appears to come from your domain, and you'll never see it happening. And since February 2024, Gmail and Yahoo require a valid DMARC record for bulk senders — so without it your legitimate email is likelier to hit spam or be rejected.

Is setting this up complicated?

The records are a few lines of DNS, but getting them right — and keeping them right as you add tools like a CRM or newsletter — is fiddly and easy to break. MailSurety sets all three up and monitors them for you, in plain English.

Does this let anyone read my email?

No. DMARC reports contain only statistics — which servers sent mail as you and whether it passed. Never message content, subjects or attachments. Your real email never passes through MailSurety.