SPF, DKIM and DMARC checkup
Three DNS records tell the rest of the world which mail really comes from your domain. This checkup reads them the way a receiving server does and translates every term it finds.
The sender line of an email proves nothing
Email was designed like a paper envelope. The sender writes the return address and nobody checks it. A server in any country can send out a message whose From line shows your domain. Three later additions close that gap, and all three live in your DNS zone as TXT records.
- SPF, at the domain itself
- A list of the servers allowed to send for the domain. The receiver compares the connecting IP address with the list.
- DKIM, at
selector._domainkey - A public key. The sending service signs each message with the matching private key, so the receiver can tell that nobody altered the message and which domain vouches for it.
- DMARC, at
_dmarc - Your instruction for mail that passes neither test under your own domain name: deliver it, send it to spam or refuse it. It also names a mailbox for daily reports.
Since February 2024, Gmail and Yahoo turn away bulk mail from domains that lack these records, and Microsoft followed in 2025 for Outlook.com.
What the checkup looks at
It starts with your MX records, to recognize the mailbox provider (Google Workspace, Microsoft 365, Proton Mail, Fastmail and eight others). From there it knows which SPF include and which DKIM selectors to expect.
| Record | Marked as a fault | Marked as a warning |
|---|---|---|
| SPF | No record on a domain that has mail servers; two records; more than 10 DNS lookups; an include that has no SPF of its own or loops back; a misspelled term; +all; more than two lookups that return nothing | 8 to 10 lookups; ?all or no all; ptr; terms placed after all; your mailbox provider missing from the list |
| DKIM | A published key that can’t be used: RSA under 1024 bits, damaged p= value, unknown algorithm | No key under any name tried; a 1024-bit key; the test flag t=y |
| DMARC | No record; two records; no valid p=; a malformed report address or tag value | p=none; pct under 100; sp=none under a stricter policy; reports sent to another domain that hasn’t agreed to receive them |
Lookups are counted through every nested include, and that’s usually where the limit of 10 gets broken without anyone noticing. For a subdomain, the DMARC search climbs to the parent domain and applies its sp= value. The overall verdict is the worst of the three results. Three optional records (MTA-STS, TLS-RPT, BIMI) are only reported as published or not.
A domain whose whole SPF is v=spf1 -all is treated as one that sends nothing. A missing DKIM key is normal there, and the suggested DMARC is p=reject.
How to find your DKIM selector
DKIM keys have no fixed address. Each sending service picks a label, called the selector, and DNS offers no way to list them. The checkup tries about three dozen usual names, such as google, selector1, k1 and s1. So “no key found” often just means yours goes by another name.
- Send a message from your domain to a mailbox you can open.
- Display its raw source: “Show original” in Gmail, “View message source” in Outlook, “View > Message > All Headers” in Apple Mail.
- Find the line that starts with
DKIM-Signature:and read two tags.d=is the signing domain ands=is the selector.
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=mta2024; …
Here you’d enter mta2024 in the selector box. If d= shows the name of your newsletter platform and not your domain, the message is signed, but not by you, and that signature doesn’t count for DMARC. Our email header decoder reads these lines for you.
Repairing in a safe order
Make a list of everything that sends as your domain: mailboxes, newsletter platform, online store, help desk, the contact form on the website. Put each one in a single SPF record. Then switch on DKIM in every service that offers it, since DKIM survives forwarding and SPF doesn’t.
Publish DMARC with p=none and a rua= address, and read the reports for a few weeks with the DMARC report reader. Once every legitimate source passes, move to quarantine, then to reject. The record builder writes both records.
This checkup reads DNS and never sees one of your messages. It can’t confirm that a service really signs with the key it found, or that the signing domain matches your From address. For that you need the headers of a delivered message.
Questions people ask
Why do my emails go to spam when SPF, DKIM and DMARC all pass?
Authentication proves who sent the message. It doesn’t say whether people want it. Filters also weigh complaint rates, the reputation of the sending IP address and domain, the links in the message and how recipients reacted to earlier mail. Start with a blocklist lookup.
Can a domain have two SPF records?
No. Two TXT records that start with v=spf1 produce a permanent error and receivers act as if you had none. Merge them into one v=spf1 with all the include: and ip4: terms and a single all at the end.
What does “SPF PermError: too many DNS lookups” mean?
Working through your record took more than 10 DNS queries. Every include, a, mx, exists and redirect costs one, and the includes inside an include count too. Remove services you no longer use, or replace a and mx with fixed ip4: addresses, which cost nothing.
Should SPF end with ~all or -all?
With DMARC in place, either works, because DMARC decides what happens to a failing message. ~all is the safer choice while you’re still discovering senders. Never use +all, which authorizes every server on the internet.
Is p=none enough for Gmail and Yahoo?
Yes, their bulk sender rules accept p=none. All it gives you is reports, and forged mail still gets delivered. Protection begins at quarantine.
Do I need DMARC on a domain that never sends email?
That’s where it’s easiest and most useful, because a parked domain makes a convenient disguise for phishing. Publish v=spf1 -all on the domain and v=DMARC1; p=reject; at _dmarc.