SPF, DKIM and DMARC: protect your domain’s email from spoofing
Three DNS records without which mail in your name lands in spam and scammers send “invoices” to your customers.
Checked against sources: 30 September 2026

- 3 recordsSPF, DKIM and DMARC in DNS
- 5,000messages a day: Gmail and Yahoo threshold
- 1–2 wkson p=none before tightening
What each record does
- SPF lists the servers allowed to send mail from your domain.
- DKIM signs the message so the recipient can tell it was not altered in transit.
- DMARC tells the mail provider what to do with mail that fails SPF and DKIM, and sends you reports.
Why a site that “just publishes articles” needs this
Without the records, anyone can send mail as info@your-domain. Your customers get a fake invoice or login link, and trust in your address drops. Since February 2024 Gmail and Yahoo require SPF, DKIM and DMARC from anyone sending them more than 5,000 messages a day; for everyone else, missing records hurt delivery.
Records you can copy
Replace the include with the service you send mail through. The DKIM key is issued by your mail provider.
example.com. TXT "v=spf1 include:_spf.google.com -all" _dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com" ; a domain that sends no mail at all example.com. TXT "v=spf1 -all" _dmarc.example.com. TXT "v=DMARC1; p=reject"
How to enable DMARC without losing mail
- A week or two on p=none: you get reports and see every sender.
- Add any missing senders to SPF and DKIM.
- Move to p=quarantine, then p=reject.
Frequently asked
What does p=none mean in DMARC?
Report collection only. It does not stop spoofing, so Awe Check treats such a record as a risk, not protection.
Why is +all in SPF dangerous?
It lets everyone send mail from your domain, which defeats the purpose of the record.
