SPF, DMARC, and DKIM explained
The authentication triad that stops spoofing — and why DMARC policy (reject vs none) carries most of the score weight.
Email deliverability starts with authentication posture you can see in DNS — not inbox placement myths. VectoraPoint’s Email axis scores SPF, DMARC, and DKIM heavily because mailbox providers expect them.
SPF: who may send as you
An SPF TXT record (v=spf1 …) lists authorised senders. Prefer a
hard fail (-all) once includes are correct; soft fail (~all)
is weaker. Watch DNS lookup count — more than ten lookups can produce a permanent
error. Flatten or redesign includes rather than stacking vendors forever.
DKIM: cryptographic signature
DKIM keys live at selector._domainkey. Discovery is brute-force on
common selectors, so a miss in an audit is a lower bound — you may have an obscure
selector. Still, production mail should publish at least one known selector for
each major sending path.
DMARC: the policy that binds them
DMARC at _dmarc tells receivers what to do when SPF/DKIM fail to
align. p=none is monitoring; quarantine and
reject enforce. In our cohorts DMARC was near-universal among serious
domains, with many already at reject. Reporting addresses (rua) help
you see abuse without guessing.
Run the Email Delivery audit to see SPF/DMARC/DKIM status and the points at stake before you change production DNS.