Skip to content
EnterraHost
Products
Tools
Hosting Email Support Client Area Find a domain

Add SPF, DKIM and DMARC

Three DNS records decide whether the rest of the internet believes your mail came from you. Without them a message can be perfectly legitimate and still be treated as suspect, because the receiving server has nothing telling it your domain authorised the send.

They are not one setting in three places. Each answers a different question, and they are strongest together.

SPF says which servers may send for you

SPF is a TXT record listing the servers allowed to send mail from your domain. A receiving server reads it and checks whether the machine that delivered the message is on the list.

The mistake that breaks SPF is having two SPF records. It is one record per domain, and a second one does not extend the first — it makes the result ambiguous and the domain fails the check. If you are combining your mail with another service that sends on your behalf, both belong in the same record.

DKIM signs the message

DKIM puts a cryptographic signature on every outgoing message, and a public key in DNS lets the receiver verify it. Unlike SPF, which is about the server, this is about the message. It proves the mail was not altered on the way.

It also survives forwarding, which SPF does not. That is the practical difference and a common reason a legitimate message fails authentication after a mailing list passes it on.

DMARC says what to do when the first two fail

DMARC is the policy, and it is the one that stops somebody else sending mail as your domain. It tells the receiver what to do with a message that fails SPF and DKIM: take no action, quarantine it, or reject it. It also asks for reports, which land in your inbox and show who is sending as you.

Start it on the gentlest setting. A DMARC record set to reject mail is correct eventually and expensive on day one, because any legitimate sender you have not listed starts being refused. Move to a stricter policy once the reports stop showing surprises.

Where the records go, and how to check

All three are DNS records on the domain, so they live wherever your DNS is managed. If the domain is registered here, that is the DNS panel in the toolbox.

Unlike a website change, DNS has to propagate before it can be tested, and a resolver keeps the answer it already holds until its copy expires. A record can be correct and invisible for a while — a DNS lookup from five regions shows whether it has been seen yet or is still settling.

A mailbox works without any of this. The difference shows up in whether your mail arrives in an inbox or a spam folder, which is why it belongs in the setup rather than in a later cleanup.

Every guide in this category is on the Business Email page.