HeadlinesBriefing HeadlinesBriefing.com

How to set up SPF, DKIM, and DMARC for your domain

Hacker News •
×

It's way too common to overlook email authentication when you set up automated email. You connect your email provider, send a test message, and it lands in spam. Or Gmail bounces it with a 550 5.7.26 error about an unauthenticated sender. This guide explains how a sending domain is authenticated, which helps keep your messages out of spam.

The three key email security components are SPF, DKIM, and DMARC. They let receiving mail servers check whether a message is authorized to use your domain, and they work together: SPF authorizes the sending server's IP address, DKIM adds a cryptographic signature to prove message integrity, and DMARC uses both results to check alignment with the visible sender address and enforce your policy. Getting them right won't guarantee inbox placement, but a missing record can keep ordinary mail from arriving.

Gmail's sender guidelines require SPF or DKIM even for small senders, and all three for senders reaching roughly 5,000 messages a day to personal Gmail accounts. We suggest you set them up right away when you connect your domain. We'll use Mailfully's domain setup here to show how everything works. If you use another provider, the record values will differ, but you'll make the same two checks: are the records published correctly, and does a message sent through your app actually pass?

All three are DNS records: short pieces of text published at your DNS host, such as Cloudflare, that any mail server can look up. The diagram below follows one message from your email provider to the receiving server. It shows which part of the message each check reads, which DNS record the server looks up for it, and what happens when DMARC passes or fails. Notice that each check reads a different domain from the same message. SPF uses the Return-Path, DKIM uses the signature's d= domain, and DMARC uses the From address. Most setup problems come from one of those domains not being the one you expected.

Source: Hacker News · Summarized by HeadlinesBriefing