Blog

SPF, DMARC, and DKIM explained

Email Delivery

The authentication triad that stops spoofing — and why DMARC policy (reject vs none) carries most of the score weight.

Email deliverability starts with authentication posture you can see in DNS — not inbox placement myths. VectoraPoint’s Email axis scores SPF, DMARC, and DKIM heavily because mailbox providers expect them.

SPF: who may send as you

An SPF TXT record (v=spf1 …) lists authorised senders. Prefer a hard fail (-all) once includes are correct; soft fail (~all) is weaker. Watch DNS lookup count — more than ten lookups can produce a permanent error. Flatten or redesign includes rather than stacking vendors forever.

DKIM: cryptographic signature

DKIM keys live at selector._domainkey. Discovery is brute-force on common selectors, so a miss in an audit is a lower bound — you may have an obscure selector. Still, production mail should publish at least one known selector for each major sending path.

DMARC: the policy that binds them

DMARC at _dmarc tells receivers what to do when SPF/DKIM fail to align. p=none is monitoring; quarantine and reject enforce. In our cohorts DMARC was near-universal among serious domains, with many already at reject. Reporting addresses (rua) help you see abuse without guessing.

Run the Email Delivery audit to see SPF/DMARC/DKIM status and the points at stake before you change production DNS.

Audit my site More posts