Digismak

SPF, DKIM and DMARC explained

SPF, DKIM and DMARC are three DNS records that prove your email really comes from your domain. Here’s what each does, plus a free checker for yours.

Updated

Check your SPF, DKIM and DMARC records

Enter a domain to see its mail records as the rest of the internet sees them. The checker reads public DNS only, changes nothing, and needs no account.

What SPF, DKIM and DMARC do, in one minute

Each record answers one question a receiving mail server asks about a message that claims to come from your domain:

SPF, DKIM and DMARC at a glance
RecordThe question it answersWhere it livesExample
SPFIs this server allowed to send mail for the domain?A TXT record on the domainv=spf1 include:_spf.google.com ~all
DKIMDid the domain sign this message, and is it unchanged?A TXT record at selector._domainkeyv=DKIM1; k=rsa; p=MIIBIjAN…
DMARCIf SPF and DKIM don’t match the From address, what should I do?A TXT record at _dmarcv=DMARC1; p=quarantine; rua=mailto:…

SPF and DKIM prove where a message came from. DMARC ties them to the address people actually see in the From line, and tells receivers what to do when that proof is missing.

What is SPF?

SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. When a message arrives from yourcompany.com, the receiving server looks up the SPF record and checks whether the sending server is on the list.

A record starts with v=spf1, lists senders with mechanisms like include: (another domain’s list, such as your email provider’s) or ip4:, and ends with a rule for everyone else:

  • ~all (softfail): mail from other servers is suspicious. The common, safe setting.
  • -all (fail): mail from other servers should be rejected.
  • ?all (neutral) says nothing, and +all lets any server in the world send as you. Avoid both.

Two rules catch people out. A domain can have only one SPF record; with two, SPF fails for all mail. And checking a record may take at most 10 DNS lookups, counting every include:, a, mx and the includes inside them. Each email tool you add usually adds an include, so busy domains hit the limit without noticing. The checker above counts lookups for you.

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a digital signature to every message. Your email provider signs outgoing mail with a private key and publishes the matching public key in your DNS. The receiving server fetches that key and checks the signature. If it matches, the message really came from a server holding your key and wasn’t changed on the way.

The public key sits at a selector: a name your provider picks, like google._domainkey.yourcompany.com for Google Workspace or selector1._domainkey for Microsoft 365. You can have several selectors at once, one per service that sends as you.

How to set up DKIM

  1. In your email provider’s admin settings, find the DKIM or “authenticate email” page and generate a key (2048-bit if you’re asked).
  2. Copy the record it gives you, a TXT record or a CNAME, into your domain’s DNS.
  3. Wait for DNS to update, then turn signing on in the provider’s settings.
  4. Send yourself a test and look for dkim=pass in the message headers, or run the checker above.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) closes the loophole the other two leave open. SPF checks the hidden envelope sender and DKIM checks whichever domain signed the message, and neither has to match the From address a person reads. DMARC requires that at least one of them passes and lines up with the From domain. This matching is called alignment.

The record sets a policy for mail that fails:

  • p=none: deliver it anyway and send me reports. Where everyone should start.
  • p=quarantine: send it to spam.
  • p=reject: refuse it.

Add rua=mailto:you@yourcompany.com to receive daily reports of who is sending as your domain. Read them for a few weeks, fix any real service that fails, then move to quarantine and later reject. Jumping straight to reject can block your own newsletter tool or website contact form.

SPF vs DKIM vs DMARC: how they work together

Picture someone sending a fake invoice as billing@yourcompany.com. Their server isn’t in your SPF record, so SPF fails. They can’t sign with your DKIM key, so DKIM fails. Your DMARC policy then tells Gmail or Outlook to reject or quarantine it, and the report tells you it happened.

You need both SPF and DKIM because each breaks in different places. When a message is forwarded, the forwarding server isn’t in your SPF record, so SPF fails, but the DKIM signature survives. When a mailing list adds a footer, DKIM can break while SPF still passes for the list’s own domain. With DMARC in place, one aligned pass is enough.

Do you need all three?

Yes, for mail to reliably reach inboxes. Since February 2024, Gmail and Yahoo require every sender to have SPF or DKIM, and anyone sending more than 5,000 messages a day to Gmail to have SPF, DKIM and a DMARC record. Microsoft began applying similar rules to high-volume senders on Outlook.com in May 2025. Smaller senders without them increasingly land in spam.

How Digismak sets them up for you

When you connect a domain to Digismak, setup adds all three. Cloudflare Email Routing adds an SPF record for your domain. Cloudflare Email Sending adds its own SPF and a DKIM key on a sending subdomain, so every message is signed for your domain. If you had no DMARC record, setup adds one at p=none, and the admin console has a button to tighten it once you know who else sends as you. The last setup step sends a real email through the whole path and checks the signature. Read more about how Digismak works with Cloudflare email.

Questions

What is the difference between SPF, DKIM and DMARC?

SPF lists the servers allowed to send for your domain. DKIM signs each message so receivers can check it came from you unchanged. DMARC requires one of them to pass and match the From address, and says what to do with mail that fails.

DMARC vs DKIM: do I need both?

Yes. DKIM is a signature; DMARC is the policy that makes signatures matter. Without DMARC, a failed DKIM check rarely stops spoofed mail. Without DKIM, DMARC has only SPF to rely on, and SPF breaks when mail is forwarded.

How do I check my SPF, DKIM and DMARC records?

Use the checker at the top of this page. It looks up your MX, SPF and DMARC records in public DNS, counts SPF lookups, and tries the DKIM selectors that common providers use.

How do I set up DKIM?

Generate a key in your email provider’s admin settings, add the TXT or CNAME record it gives you to your DNS, then turn signing on. Check the result with a test email or the checker above.

Can a domain have two SPF records?

No. With two SPF records, SPF returns an error for every message. Merge them into one record that includes every service that sends as your domain.

What DMARC policy should I start with?

Start with p=none and a rua address for reports. After a few weeks of clean reports, move to p=quarantine, then p=reject.

Why can’t the checker find my DKIM record?

DKIM keys sit at a selector your provider chooses, and there’s no way to list them from outside. The checker tries the common ones. If your provider uses a custom selector, its DKIM settings page shows the name.

Is the SPF, DKIM and DMARC checker free?

Yes. It reads public DNS records, the same ones any mail server sees, and doesn’t change anything or need an account.

Get SPF, DKIM and DMARC set up for you

Free during early access. Sending needs Cloudflare’s $5/month Workers Paid plan.