Key facts
- SPF, DKIM and DMARC are all published as TXT records in your domain's DNS.
- A domain should have only one SPF record; two SPF records cause SPF to fail.
- SPF has a limit of 10 DNS lookups, and each include: counts towards it.
- DKIM keys are generated by your email provider and published at a selector such as selector1._domainkey.
- DMARC lives at _dmarc.yourdomain and usually starts at p=none for monitoring.
- Major mailbox providers now expect bulk senders to have SPF, DKIM and DMARC in place.
- dijitul Complete Hosting includes Cloudflare DNS management for £1 a day + VAT.
What SPF, DKIM and DMARC do
These three DNS records prove that email claiming to come from your domain really is from you. Without them, your messages are more likely to land in spam, and criminals find it easier to spoof your address.
- SPF (Sender Policy Framework) lists the servers allowed to send email for your domain.
- DKIM (DomainKeys Identified Mail) adds a digital signature to each message, checked against a public key in your DNS.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do when SPF or DKIM fails, and sends you reports.
All three are TXT records. You add them wherever your DNS is managed, which may be your registrar, your host or Cloudflare.
Step 1: set up SPF
First, list every service that sends email as your domain: your mailbox provider, your website (contact forms, shop receipts), and any newsletter or invoicing tool. Then create one TXT record on the root of the domain. Examples for example.co.uk:
- Microsoft 365 only: v=spf1 include:spf.protection.outlook.com ~all
- Google Workspace only: v=spf1 include:_spf.google.com ~all
- Mail sent from your own server plus Microsoft 365: v=spf1 a mx include:spf.protection.outlook.com ~all
~all is a soft fail, which is a safe starting point. -all is stricter. Never publish two SPF records: merge them into one. Keep under the limit of 10 DNS lookups.
Step 2: set up DKIM
DKIM keys are created by whoever sends your email, so the steps depend on the provider:
- In your email admin panel, find the DKIM or domain authentication setting.
- Generate a key. The provider gives you a hostname and value.
- Add it to DNS exactly as given. Microsoft 365 uses two CNAME records, such as selector1._domainkey.example.co.uk. Google Workspace and Plesk mail usually give a TXT record starting v=DKIM1; k=rsa; p= followed by a long key.
- Return to the email panel and switch DKIM signing on.
Each sending service, such as a newsletter platform, needs its own DKIM record with its own selector.
Step 3: set up DMARC
Add a TXT record at _dmarc.example.co.uk. Start in monitoring mode:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.co.uk
p=none changes nothing about delivery. It just asks receivers to send daily aggregate reports to the rua address. Read those reports for two to four weeks to find any legitimate sender you missed. Then tighten the policy in stages:
- v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.co.uk sends a quarter of failing mail to spam.
- Raise pct to 100 once reports are clean.
- v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.co.uk blocks failing mail completely.
Common mistakes to avoid
- Publishing a second SPF record for a new service instead of adding an include: to the existing one.
- Forgetting the website itself, so contact form and shop emails fail SPF.
- Switching straight to p=reject before reading DMARC reports.
- Pasting a DKIM key with spaces or line breaks in the wrong place.
- Adding records at the old DNS provider after the nameservers have moved.
Check your records, and how dijitul helps
After any change, send a test email to a Gmail or Outlook address and view the original message headers. Look for spf=pass, dkim=pass and dmarc=pass. DNS changes can take a little while to be seen everywhere, especially if old records had a long TTL.
If your DNS is with dijitul, you do not have to do this alone. dijitul Complete Hosting includes Cloudflare DNS set up and managed for you, so we add and check SPF, DKIM and DMARC records alongside your MX records. It costs £1 a day + VAT and also includes 10 POP3/IMAP email accounts on your domain, daily backups kept for 14 days, free SSL and migration. See also email hosting or order online.
Frequently asked questions
Do I need SPF, DKIM and DMARC for a small business?
Yes. Even a small business sending a handful of emails a day benefits. The big mailbox providers use these records to decide whether to trust your mail, and missing records are a common reason for business email going to spam. They also make it harder for criminals to send fake invoices that appear to come from your domain.
Can I have two SPF records?
No. A domain must have only one SPF record. If there are two TXT records starting v=spf1, receiving servers treat SPF as a permanent error and it fails. Combine them into one record instead, for example v=spf1 include:spf.protection.outlook.com include:_spf.google.com ~all, and keep the total under ten DNS lookups.
What DMARC policy should I start with?
Start with p=none and a reporting address, for example v=DMARC1; p=none; rua=mailto:dmarc-reports@example.co.uk. This changes nothing about delivery but sends you reports showing who is sending as your domain. After a few weeks of clean reports, move to p=quarantine, then p=reject, so spoofed email is blocked.
Should I use ~all or -all in my SPF record?
~all is a soft fail: unlisted senders are treated as suspicious but not always rejected. -all is a hard fail: unlisted senders should be rejected. Start with ~all while you confirm every sender is listed. Once DMARC is enforcing, the choice matters less, because DMARC policy decides what happens to failing mail.
How long do SPF, DKIM and DMARC changes take to work?
New records are often seen within minutes, but it can take up to the TTL of any old record before every server sees the change. A TTL of one hour is common. Send a test email to a Gmail or Outlook address and check the headers for spf=pass, dkim=pass and dmarc=pass to confirm.
Will dijitul set up SPF, DKIM and DMARC for me?
Yes. dijitul Complete Hosting includes Cloudflare DNS set up and managed by our UK team, so we add and check SPF, DKIM, DMARC and MX records for your domain. The plan costs £1 a day + VAT and also includes 10 POP3/IMAP email accounts, daily backups kept for 14 days, free SSL, migration and one domain a year.
Related
Set it up and forget about it
Managed hosting, Plesk, Cloudflare DNS, daily backups and your domain for £1 a day + VAT. We move your site for you.