SPF, DKIM and DMARC in plain English for small businesses
What SPF, DKIM and DMARC records do, what they look like, why your website's form emails need them, and how to check and tighten them safely.
- Updated
Short answer
SPF, DKIM and DMARC are three DNS records that prove email from your domain really is from you: SPF lists the servers allowed to send it, DKIM signs each message, and DMARC tells receivers what to do when the checks fail. Since February 2024, Gmail and Yahoo have required SPF or DKIM from every sender and all three from bulk senders. Your website sends email as your domain too, so its form emails need to pass them.
Key takeaways
- SPF lists who may send email for your domain, DKIM signs each message, and DMARC sets the rule when checks fail.
- A domain has only one SPF record, and every service that sends as you must be added to it.
- DMARC passes only when SPF or DKIM passes for the same domain as the From address.
- Your website is a sender too, so make sure its form emails pass before you tighten DMARC.
- Start DMARC at p=none, read the reports, then move through quarantine to reject.
What is email authentication?
Email authentication is the set of DNS records, SPF, DKIM and DMARC, that let a receiving mail server check that an email claiming to come from your domain was sent by you or a service you allow.
On this page
What are SPF, DKIM and DMARC?
SPF, DKIM and DMARC are three text records in your domain's DNS that let other mail servers check whether an email using your domain is genuine. Together they're known as email authentication. Without them, anyone can put your address in the From line, and receiving servers have nothing to tell your real messages from forged ones.
SPF: who may send for your domain
SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. A receiving server looks at where a message came from and checks it against that list. Each service you send through, such as Google Workspace or Mailgun, gives you a short "include" to add to it.
DKIM: a signature on each message
DKIM (DomainKeys Identified Mail) adds a digital signature to every email. Your mail service signs each message with a private key, and you publish the matching public key in DNS, so receivers can check the signature and see the message wasn't altered on the way.
DMARC: the rule when checks fail
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails, and asks them to send you reports. It adds one condition the other two lack: the domain that passed SPF or DKIM must match the domain in the From address the reader sees. This is called alignment, and it stops a spammer passing SPF for their own domain while showing yours.
What do the records look like?
Each one is a TXT record, added wherever your domain's DNS is managed: usually your domain registrar, your web host or Cloudflare. Here is a typical set for a business that uses Google Workspace for its mailboxes and Mailgun for its website's email, with example.co.uk standing in for your domain.
; SPF, on the domain itself (@) v=spf1 include:_spf.google.com include:mailgun.org ~all ; DKIM, at google._domainkey v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA... ; DMARC, at _dmarc v=DMARC1; p=none; rua=mailto:[email protected]
The SPF record allows Google's and Mailgun's servers and soft-fails everything else (~all). The DKIM record holds Google's public key under its default name, google._domainkey, and Mailgun gives you a separate DKIM record of its own. The DMARC record sits at _dmarc, takes no action yet (p=none) and asks for reports to go to the address after rua=.
Two rules catch people out. A domain can have only one SPF record, so add each new service to the existing record rather than creating a second. And checking an SPF record may take no more than 10 DNS lookups; every include counts, and some count more than once, so a long list of services can push it over the limit and make SPF fail.
What did Google and Yahoo change in 2024?
From February 2024, Gmail and Yahoo required every sender to set up SPF or DKIM, and anyone sending more than 5,000 messages a day to their users to set up all three. Mail that doesn't meet the rules can be rejected or sent to spam.
The bulk senders' list goes further. Google asks for a DMARC record (p=none is enough), alignment with the From address, one-click unsubscribe on marketing email and a spam complaint rate below 0.3%. Yahoo's rules are much the same. Microsoft followed for Outlook.com, and from May 2025 began sending mail from non-compliant domains that send over 5,000 messages a day to Junk.
A small business website sends nowhere near 5,000 emails a day, so the rule that applies to it is SPF or DKIM. Setting up all three costs nothing, though, and DMARC is the only one of the three that stops other people sending email as your domain.
How do they affect your website's contact form?
Your website is one of the senders on your domain, so its form emails have to pass the same checks as everything else. On WordPress and other self-hosted sites, the form email usually leaves from your web server with an address on your domain in From. If that server isn't in your SPF record and doesn't sign with DKIM for your domain, the email fails and is likely to land in spam.
The fix is to send the site's email through a service that is in your SPF record and signs for your domain. On WordPress that means an SMTP plugin, and our guide to setting up SMTP for WordPress contact forms covers the plugins and services. For more on the symptoms, see why WordPress form emails go to spam.
Check the form's From address too. A form that puts the visitor's email in From, such as [email protected], can't pass DMARC, because your server isn't allowed to send for gmail.com. Put your own address in From and the visitor's in Reply-To.
At p=none, a form email that fails is left to the receiver's spam filter. Once you tighten DMARC to p=reject, receivers are told to refuse it, and the enquiry disappears without anyone noticing.
How do you check your records?
Free online checkers will read your records and tell you what's missing or broken. Two good places to start:
Google Admin Toolbox, whose Check MX tool checks your MX and SPF records (and DKIM, if you give it the selector), and whose Messageheader tool reads the headers of a message you paste in.
MXToolbox, whose SuperTool has separate SPF, DKIM and DMARC lookups and a blocklist check.
Then check a real message from your form, since that's what has to pass. Send yourself an enquiry through your own form at a Gmail address, open it, choose More and then Show original, and look for passes for SPF, DKIM and DMARC near the top. A pass for SPF or DKIM on a different domain, such as your web host's, means the email isn't aligned with your domain yet.
How do you roll out DMARC safely?
Roll DMARC out in stages: start with a policy that does nothing, and tighten it only when the reports show all your genuine mail passing. Google recommends having SPF and DKIM in place at least 48 hours before you add DMARC.
-
List everything that sends as you
Your mailboxes, your website, your newsletter tool, and any booking, invoicing or CRM software that emails customers. Each one needs to pass SPF or DKIM for your domain.
-
Publish DMARC at p=none
Add the record at _dmarc. Nothing changes for delivery yet, and reports start arriving at the rua address.
TXT record at _dmarcv=DMARC1; p=none; rua=mailto:[email protected]
-
Read the reports and fix failures
The reports are XML files, so a free DMARC report viewer helps. Fix any genuine sender that fails before going further.
-
Move to quarantine a step at a time
Change the policy to p=quarantine with a small pct value, such as pct=10, so only a share of failing mail goes to spam. Raise it as the reports stay clean.
TXT record at _dmarcv=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]
-
Finish at reject
Once nothing genuine fails, p=reject tells receivers to refuse mail that fails, which stops other people sending as your domain.
Google suggests watching at p=none for at least a week before you move on. A small business with a handful of senders can go faster than a large company, but don't skip the reports. They're how you find the forgotten booking system or old website whose emails would otherwise be rejected.
What else stops enquiries going missing?
Good records make form emails far more reliable, but email still fails for reasons DNS can't fix, such as a full mailbox, an expired SMTP password or a filter rule someone added. Keep a copy of each submission on your site where your form tool allows it, and send a test enquiry now and then.
If you'd rather not rely on email alone, Formcrier sends each form submission to your phone on WhatsApp, a text, Telegram, Slack or Microsoft Teams within seconds, without going through your domain's email. See how Formcrier works. It's free for 10 alerts a month.
Frequently asked questions
No. A domain can only have one SPF record, so merge every include into a single record. Two records make SPF checks fail.
Google recommends ~all for Google Workspace, which marks mail from unlisted servers as suspicious. Microsoft recommends -all for Microsoft 365 domains that also use DKIM and DMARC. Follow your mailbox provider's advice.
Many changes show up within a few hours, but Mailgun, for example, says to allow 24 to 48 hours for them to spread. Check with one of the free tools before you assume a record is wrong.
Gmail's rules don't require it below 5,000 messages a day. It's still worth having, because its reports show who is sending as your domain, and a quarantine or reject policy stops others forging it.
Sources and method
The 2024 requirements were checked against Google's and Yahoo's own sender pages, and the record formats against Google, Microsoft and Mailgun's set-up guides, on 1 Oct 2026.
- Google, Email sender guidelines, accessed 1 Oct 2026
- Yahoo Sender Hub, Sender Best Practices, accessed 1 Oct 2026
- Microsoft Defender for Office 365 Blog, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders, accessed 1 Oct 2026
- Google Workspace Admin Help, Recommended DMARC rollout, accessed 1 Oct 2026
- Google Workspace Admin Help, Set up SPF, accessed 1 Oct 2026
- Google Workspace Admin Help, Set up DKIM, accessed 1 Oct 2026
- Google Workspace Admin Help, Troubleshoot DMARC issues, accessed 1 Oct 2026
- Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain, accessed 1 Oct 2026
- Mailgun Documentation, Domain Verification, accessed 1 Oct 2026
- IETF, RFC 7208: Sender Policy Framework (SPF), accessed 1 Oct 2026
- Google Admin Toolbox, Check MX, accessed 1 Oct 2026
- MXToolbox, SuperTool, accessed 1 Oct 2026
Tim builds websites for UK service businesses and made Formcrier after clients kept missing enquiries sent by email.