SPF, DKIM and DMARC checkup

Three DNS records tell the rest of the world which mail really comes from your domain. This checkup reads them the way a receiving server does and translates every term it finds.

I know my DKIM selector

It is the value after s= in the DKIM-Signature header of a message you sent. Put commas between several names. About three dozen usual names are tried without asking.

Or try gmail.com · outlook.com · wikipedia.org

The domains you look up are not saved. To slow down abuse, a one-way hash of your IP address is held for two hours at most, then deleted.

The sender line of an email proves nothing

Email was designed like a paper envelope. The sender writes the return address and nobody checks it. A server in any country can send out a message whose From line shows your domain. Three later additions close that gap, and all three live in your DNS zone as TXT records.

SPF, at the domain itself
A list of the servers allowed to send for the domain. The receiver compares the connecting IP address with the list.
DKIM, at selector._domainkey
A public key. The sending service signs each message with the matching private key, so the receiver can tell that nobody altered the message and which domain vouches for it.
DMARC, at _dmarc
Your instruction for mail that passes neither test under your own domain name: deliver it, send it to spam or refuse it. It also names a mailbox for daily reports.

Since February 2024, Gmail and Yahoo turn away bulk mail from domains that lack these records, and Microsoft followed in 2025 for Outlook.com.

What the checkup looks at

It starts with your MX records, to recognize the mailbox provider (Google Workspace, Microsoft 365, Proton Mail, Fastmail and eight others). From there it knows which SPF include and which DKIM selectors to expect.

RecordMarked as a faultMarked as a warning
SPFNo record on a domain that has mail servers; two records; more than 10 DNS lookups; an include that has no SPF of its own or loops back; a misspelled term; +all; more than two lookups that return nothing8 to 10 lookups; ?all or no all; ptr; terms placed after all; your mailbox provider missing from the list
DKIMA published key that can’t be used: RSA under 1024 bits, damaged p= value, unknown algorithmNo key under any name tried; a 1024-bit key; the test flag t=y
DMARCNo record; two records; no valid p=; a malformed report address or tag valuep=none; pct under 100; sp=none under a stricter policy; reports sent to another domain that hasn’t agreed to receive them

Lookups are counted through every nested include, and that’s usually where the limit of 10 gets broken without anyone noticing. For a subdomain, the DMARC search climbs to the parent domain and applies its sp= value. The overall verdict is the worst of the three results. Three optional records (MTA-STS, TLS-RPT, BIMI) are only reported as published or not.

A domain whose whole SPF is v=spf1 -all is treated as one that sends nothing. A missing DKIM key is normal there, and the suggested DMARC is p=reject.

How to find your DKIM selector

DKIM keys have no fixed address. Each sending service picks a label, called the selector, and DNS offers no way to list them. The checkup tries about three dozen usual names, such as google, selector1, k1 and s1. So “no key found” often just means yours goes by another name.

  1. Send a message from your domain to a mailbox you can open.
  2. Display its raw source: “Show original” in Gmail, “View message source” in Outlook, “View > Message > All Headers” in Apple Mail.
  3. Find the line that starts with DKIM-Signature: and read two tags. d= is the signing domain and s= is the selector.
DKIM-Signature: v=1; a=rsa-sha256; d=example.com; s=mta2024; …

Here you’d enter mta2024 in the selector box. If d= shows the name of your newsletter platform and not your domain, the message is signed, but not by you, and that signature doesn’t count for DMARC. Our email header decoder reads these lines for you.

Repairing in a safe order

Make a list of everything that sends as your domain: mailboxes, newsletter platform, online store, help desk, the contact form on the website. Put each one in a single SPF record. Then switch on DKIM in every service that offers it, since DKIM survives forwarding and SPF doesn’t.

Publish DMARC with p=none and a rua= address, and read the reports for a few weeks with the DMARC report reader. Once every legitimate source passes, move to quarantine, then to reject. The record builder writes both records.

This checkup reads DNS and never sees one of your messages. It can’t confirm that a service really signs with the key it found, or that the signing domain matches your From address. For that you need the headers of a delivered message.

Questions people ask

Why do my emails go to spam when SPF, DKIM and DMARC all pass?

Authentication proves who sent the message. It doesn’t say whether people want it. Filters also weigh complaint rates, the reputation of the sending IP address and domain, the links in the message and how recipients reacted to earlier mail. Start with a blocklist lookup.

Can a domain have two SPF records?

No. Two TXT records that start with v=spf1 produce a permanent error and receivers act as if you had none. Merge them into one v=spf1 with all the include: and ip4: terms and a single all at the end.

What does “SPF PermError: too many DNS lookups” mean?

Working through your record took more than 10 DNS queries. Every include, a, mx, exists and redirect costs one, and the includes inside an include count too. Remove services you no longer use, or replace a and mx with fixed ip4: addresses, which cost nothing.

Should SPF end with ~all or -all?

With DMARC in place, either works, because DMARC decides what happens to a failing message. ~all is the safer choice while you’re still discovering senders. Never use +all, which authorizes every server on the internet.

Is p=none enough for Gmail and Yahoo?

Yes, their bulk sender rules accept p=none. All it gives you is reports, and forged mail still gets delivered. Protection begins at quarantine.

Do I need DMARC on a domain that never sends email?

That’s where it’s easiest and most useful, because a parked domain makes a convenient disguise for phishing. Publish v=spf1 -all on the domain and v=DMARC1; p=reject; at _dmarc.