RedWaterHST
← All answers

SPF, DKIM and DMARC: keeping your email out of spam

If email from your domain keeps landing in spam folders, the cause is usually missing authentication records rather than anything you wrote. Receiving servers check three DNS records to decide whether a message really came from you. Miss them and you look like a forger.

The three records, in one line each

  • SPF lists which servers are allowed to send email for your domain.
  • DKIM adds a cryptographic signature proving the message wasn't altered in transit.
  • DMARC tells receivers what to do when a message fails those checks, and sends you reports about who's sending as your domain.

What they look like

All three are TXT records in your DNS zone. Roughly:

yourdomain.com          TXT  "v=spf1 include:mail.yourhost.com ~all"
default._domainkey      TXT  "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."
_dmarc.yourdomain.com   TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

The exact values depend on who sends your email. Your mail host provides the SPF include and the DKIM key. Start DMARC with p=none to observe reports for a couple of weeks before tightening it to quarantine or reject.

How to test

Send a message to mail-tester.com and read the score. It shows exactly which of the three checks passed. Aim for all three green; two out of three still leaks into spam at strict receivers like Google and Microsoft.

On our hosting

We set up SPF and DKIM for mailboxes hosted with us as part of every migration, and we'll help you add a sane DMARC record if you don't have one. If you send through a third party like Mailchimp or a CRM, remember that each sender needs to be added to SPF and have its own DKIM key. That's the single most common gap we see.

Still stuck?

Open a ticket and a real engineer will sort it out with you.