← Back to blog

Email Authentication Explained: SPF, DKIM and DMARC in Plain English

05 September 2026·5 min read
Quick answer: SPF, DKIM and DMARC are three separate checks, published in your domain's DNS settings, that work together to prove an email claiming to be from you is actually authorised by you. SPF lists which servers are allowed to send on your behalf, DKIM cryptographically signs the message so it can't be tampered with in transit, and DMARC tells receiving inboxes what to do if a message fails those checks — plus sends you reports on who's sending mail as your domain. Get all three set up properly and your legitimate email is far more likely to land in the inbox instead of spam. 📈

I get asked "why are my emails going to spam" more than almost any other question, and a big chunk of the time the answer has nothing to do with subject lines or send times — it's that the business never properly set up email authentication, so receiving mail providers can't confirm the message is really coming from who it claims to be from. This is one of those unglamorous bits of infrastructure nobody thinks about until deliverability quietly tanks 💖, and it's genuinely less scary than the acronyms make it sound.

What most businesses get wrong

The most common mistake is treating this as a "set once and forget" job, or never setting it up at all because "the email works fine" — until it doesn't. Every time you add a new tool that sends email on your behalf — invoicing software, a CRM, a booking system, a marketing platform — and don't update your records to include it, you either create a gap or break deliverability for that tool. The other mistake is assuming DMARC is a nice-to-have. It used to be. Since the big inbox providers introduced stricter bulk-sender requirements in recent years, DMARC is now effectively expected for anyone sending meaningful volumes of email, not optional extra credit. If you haven't checked this in the last year, and you've added any new sending tool since, you likely have a gap you don't know about.

The DMARC Rollout Checklist (the safe order to do this in)
  1. Confirm SPF is set up and lists every service that sends email as you — your email provider, CRM, invoicing tool, booking system and marketing platform.
  2. Confirm DKIM is enabled individually for each of those sending services.
  3. Publish a DMARC record starting at "monitor only" — a policy that just collects reports without blocking anything. This is the safe starting point, always.
  4. Review the reports for two to four weeks to see what's actually sending mail as your domain.
  5. Fix any gaps the reports reveal.
  6. Move DMARC gradually: monitor → quarantine (treat failures as suspicious, usually routed to spam) → reject (block failures outright) — only once you're confident every legitimate sender is passing.
  7. Recheck this whole list every time you add a new tool that sends email on your behalf.
A B2B firm with a long sales cycle: added a new CRM that sent proposal follow-ups from their domain. Deliverability to key prospects quietly dropped, traced back weeks later to a missing SPF entry for the new tool — a one-day fix once someone finally found it, but it had cost real momentum with prospects who simply never saw the follow-up.
A local service business: switched email marketing platforms and their newsletter started landing in spam. The DMARC report showed the old platform was still technically authorised to send as them while the new one hadn't been properly recorded yet.
A subscription/product business: jumped straight to DMARC "reject" without a monitoring period first. One overlooked internal tool got silently blocked, and some transactional receipts failed to send for a few days before anyone noticed — a cautionary tale for skipping the monitor phase.

How to actually set this up

Most of this lives in your domain's DNS settings, typically managed through wherever your domain is registered or through your website host. Exact steps vary a fair bit by provider, so there's no single universal walkthrough — your email provider or web host can usually set the records up for you or generate the specific values you need to add, which is worth using rather than guessing at syntax yourself. What is provider-agnostic is the sequence: get SPF and DKIM correct first, publish DMARC in monitor mode, actually read the reports, fix what they show, then tighten the policy in stages. Skipping straight to a strict policy before you've confirmed every legitimate sender passes is the single most common way this goes wrong.

💡 Don't jump straight to "reject." Without a monitoring period first, you risk silently blocking legitimate mail from a tool you forgot was sending on your behalf.

Mistakes to avoid

  • Never setting up DMARC at all
  • Moving straight to "reject" without a monitoring period
  • Forgetting to update SPF when you add a new sending tool
  • Assuming your web host automatically handles this — some do, many don't
  • Switching DMARC on and then never reviewing the reports it generates

Frequently asked questions

Do I need SPF, DKIM and DMARC, or just one of them?

All three work together. DMARC actually relies on SPF and/or DKIM passing to do anything useful, so publishing a DMARC record without at least one of the other two properly configured won't achieve much on its own.

Will this fix all my spam problems?

No — authentication is necessary but not sufficient. Content, sending reputation, list quality and recipient engagement all matter too. Fixing authentication removes one major reason mail lands in spam; it doesn't guarantee inbox placement.

Can I set this up myself?

Often yes, but the exact steps depend heavily on your domain host and which tools send email on your behalf. Your email provider or web host can usually set this up or point you to the right settings — for anyone not comfortable in DNS settings, it's worth asking a developer or your hosting support to do it once properly rather than guessing.

What actually happens if I just ignore this?

Rarely anything dramatic overnight. More often it shows up as a slow, hard-to-diagnose decline in open rates and deliverability as inbox providers increasingly filter unauthenticated bulk mail — which is honestly harder to fix in hindsight than setting it up properly from the start.


Keep reading 🤍

Share
Written by
Kate, founder of Chronically Online

I help Gold Coast and Brisbane businesses grow with branding, websites and marketing that actually works.

Work with me ✦