← Back to blog
ByHM&C Team(Email Infrastructure & Security Specialists)

SPF, DKIM and DMARC explained: a practical guide for non-technical teams

SPF, DKIM and DMARC are the three DNS records that determine whether your email lands in the inbox or spam. Here's what each one does, in plain language.

When you send an email from your own domain, the receiving server asks three questions: who is authorized to send from this domain? Was the message altered in transit? Does the domain have a policy for suspicious messages? SPF, DKIM and DMARC answer each of these.

SPF — who can send from your domain

SPF (Sender Policy Framework) is a TXT DNS record that lists which servers are allowed to send email on behalf of your domain.

DKIM — a digital signature on every message

DKIM (DomainKeys Identified Mail) works like a wax seal on an envelope. The sending server signs the message with a private key; the receiving server verifies the signature using the public key published in DNS.

DMARC — what to do when SPF or DKIM fail

DMARC tells the receiving server what to do when SPF or DKIM fail: do nothing (p=none), quarantine (p=quarantine), or reject (p=reject). It also sends daily reports on misuse attempts.

H2E Mail configures SPF and DKIM automatically at activation. DMARC can be added by you or the support team.