Email Authentication Explained: SPF, DKIM and DMARC in Plain English
I get asked "why are my emails going to spam" more than almost any other question, and a big chunk of the time the answer has nothing to do with subject lines or send times — it's that the business never properly set up email authentication, so receiving mail providers can't confirm the message is really coming from who it claims to be from. This is one of those unglamorous bits of infrastructure nobody thinks about until deliverability quietly tanks 💖, and it's genuinely less scary than the acronyms make it sound.
What most businesses get wrong
The most common mistake is treating this as a "set once and forget" job, or never setting it up at all because "the email works fine" — until it doesn't. Every time you add a new tool that sends email on your behalf — invoicing software, a CRM, a booking system, a marketing platform — and don't update your records to include it, you either create a gap or break deliverability for that tool. The other mistake is assuming DMARC is a nice-to-have. It used to be. Since the big inbox providers introduced stricter bulk-sender requirements in recent years, DMARC is now effectively expected for anyone sending meaningful volumes of email, not optional extra credit. If you haven't checked this in the last year, and you've added any new sending tool since, you likely have a gap you don't know about.
- Confirm SPF is set up and lists every service that sends email as you — your email provider, CRM, invoicing tool, booking system and marketing platform.
- Confirm DKIM is enabled individually for each of those sending services.
- Publish a DMARC record starting at "monitor only" — a policy that just collects reports without blocking anything. This is the safe starting point, always.
- Review the reports for two to four weeks to see what's actually sending mail as your domain.
- Fix any gaps the reports reveal.
- Move DMARC gradually: monitor → quarantine (treat failures as suspicious, usually routed to spam) → reject (block failures outright) — only once you're confident every legitimate sender is passing.
- Recheck this whole list every time you add a new tool that sends email on your behalf.
How to actually set this up
Most of this lives in your domain's DNS settings, typically managed through wherever your domain is registered or through your website host. Exact steps vary a fair bit by provider, so there's no single universal walkthrough — your email provider or web host can usually set the records up for you or generate the specific values you need to add, which is worth using rather than guessing at syntax yourself. What is provider-agnostic is the sequence: get SPF and DKIM correct first, publish DMARC in monitor mode, actually read the reports, fix what they show, then tighten the policy in stages. Skipping straight to a strict policy before you've confirmed every legitimate sender passes is the single most common way this goes wrong.
Mistakes to avoid
- Never setting up DMARC at all
- Moving straight to "reject" without a monitoring period
- Forgetting to update SPF when you add a new sending tool
- Assuming your web host automatically handles this — some do, many don't
- Switching DMARC on and then never reviewing the reports it generates
Frequently asked questions
Do I need SPF, DKIM and DMARC, or just one of them?
All three work together. DMARC actually relies on SPF and/or DKIM passing to do anything useful, so publishing a DMARC record without at least one of the other two properly configured won't achieve much on its own.
Will this fix all my spam problems?
No — authentication is necessary but not sufficient. Content, sending reputation, list quality and recipient engagement all matter too. Fixing authentication removes one major reason mail lands in spam; it doesn't guarantee inbox placement.
Can I set this up myself?
Often yes, but the exact steps depend heavily on your domain host and which tools send email on your behalf. Your email provider or web host can usually set this up or point you to the right settings — for anyone not comfortable in DNS settings, it's worth asking a developer or your hosting support to do it once properly rather than guessing.
What actually happens if I just ignore this?
Rarely anything dramatic overnight. More often it shows up as a slow, hard-to-diagnose decline in open rates and deliverability as inbox providers increasingly filter unauthenticated bulk mail — which is honestly harder to fix in hindsight than setting it up properly from the start.
Keep reading 🤍
I help Gold Coast and Brisbane businesses grow with branding, websites and marketing that actually works.
Work with me ✦