Email and DNS

Your emails land in spam? Meet SPF, DKIM and DMARC in plain words

Your emails land in spam? Meet SPF, DKIM and DMARC in plain words

You send an offer to a customer and it lands in spam. Or you get word that someone is sending emails "from you", though you sent nothing. In both cases the source is usually the same: three records are missing from the domain's configuration, SPF, DKIM and DMARC. They sound scary, but the idea behind them is simple. Let us explain them in plain words.

The problem: email is inherently easy to forge

Email was created in an era when nobody thought about fraud. By default anyone can send a message that looks as if it came from you, all they have to do is put your address as the sender. It is like sending a letter with someone else's return address on the envelope. SPF, DKIM and DMARC are three ways for recipients' servers to check whether an email really is from you.

SPF: who is allowed to send on the domain's behalf

SPF is a list of servers allowed to send email from your domain. It is as if you told the post office: "letters from me go out only from these specific mailboxes". When an email arrives claiming to be yours but from a server not on the list, the recipient knows something is off.

DKIM: a digital seal on the message

DKIM adds an invisible, digital seal to every email. The recipient's server checks whether the seal matches, and if so, it is sure the message really left your domain and nobody altered it along the way. It is like a wax-sealed envelope with your crest: if the seal is intact, you know it is the original.

DMARC: instructions on what to do with forgeries

SPF and DKIM check authenticity, but it is DMARC that tells recipients' servers what to do when an email fails the tests: let it through, drop it into spam or reject it. In addition, DMARC can send you reports about who is trying to send email on your domain's behalf, so you know whether someone is impersonating you.

In short: SPF says "who may send", DKIM says "this is definitely the original", and DMARC says "and if not, do this with it, and let me know".

What it gives you in practice

Correctly set, all three give two very concrete benefits:

  • Your emails reach the inbox, not spam: because recipients' servers trust you. That matters especially for offers, invoices and mailings.
  • Nobody impersonates your domain: it is harder to deceive your customers with a fake email "from your company", which protects your reputation.

How to check and set it

These three things are set as DNS records in the domain panel, a one-off configuration, not something to do daily. But it must be done carefully: a badly set SPF can block your own email, and an overly strict DMARC without prior testing can bounce important emails. That is why DMARC is usually introduced gradually, watching the reports.

Not sure whether your domain has this configured correctly? It is one of the first things we check when caring for a site. Get in touch, we will verify your email configuration and set it up so your emails arrive and nobody impersonates your company.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.