SPF, DKIM and DMARC: How to Land Your Emails in the Inbox
26/07/2026
If email from your business domain keeps landing in spam, or someone sends messages in your name, you are almost always missing a correct SPF, DKIM or DMARC setup. These three DNS records prove the email is really yours.
SPF — who may send on your behalf
SPF (Sender Policy Framework) is a TXT record listing the servers allowed to send mail for your domain. Example:
v=spf1 include:_spf.yourprovider.com ~all
If a message arrives from a server not on the list, the receiver treats it as suspicious.
DKIM — a digital signature
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message header. The receiving server uses your public key (published in DNS) to confirm the message was not altered and truly comes from your domain.
DMARC — policy and reporting
DMARC ties SPF and DKIM together and tells receivers what to do when a check fails. Start soft, then tighten:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com— reporting only- later
p=quarantinethenp=rejectonce confident
The right order
Set up SPF first, then DKIM (enable it in your mail service and publish the key in DNS), then DMARC at p=none. Watch the reports for a few weeks, fix legitimate sources that fail, then tighten the policy.
With our hosting plans and business email on your domain, you configure all three records from one panel, and we are glad to help with DNS so delivery is flawless.