These three DNS records tell the world which mail is really from your domain. Together they reduce spoofing and help your legitimate mail reach the inbox.
- SPF (Sender Policy Framework) lists the servers allowed to send email for your domain. Receiving servers treat mail from anywhere else with suspicion.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. The receiver uses a public key in your DNS to confirm the message was not altered and really came from your domain.
- DMARC ties SPF and DKIM together. It tells receivers what to do with mail that fails (nothing, quarantine, or reject) and sends you reports showing who is sending as your domain.
The safe way to deploy DMARC is gradually: start in monitoring (p=none) to read the reports, fix any legitimate senders that fail, then tighten to quarantine and finally reject. Rushing to reject can send your own mail to spam.
The records live in your DNS zone, and this is exactly the rollout our email security service manages.