Do I need all three of SPF, DKIM, and DMARC?
Yes, if you want your email to reach the inbox at Gmail, Yahoo, or Microsoft 365. SPF without DKIM leaves your messages vulnerable to being modified in transit. DKIM without SPF leaves your sending servers unauthenticated. Neither alone lets mailbox providers apply a consistent policy on failures, which is what DMARC adds. Google and Yahoo now require all three for any sender over 5,000 messages per day.
What is the difference between SPF and DKIM?
SPF checks that the sending server is on your approved list. DKIM checks that the message itself was signed by your private key and not tampered with in transit. SPF validates the envelope (the SMTP connection), while DKIM validates the message content (the headers and body). A spoofed sender can sometimes pass SPF by relaying through an authorized server, but they cannot fake a DKIM signature without the private key.
What does DMARC p=none, p=quarantine, and p=reject mean?
p=none tells receiving servers to apply no action on authentication failures and just send you aggregate reports. p=quarantine tells them to route failures to the spam folder. p=reject tells them to bounce the message outright. The recommended rollout is to start at p=none, monitor reports for two to four weeks, move to p=quarantine at a low percentage, climb to 100 percent, then promote to p=reject once failures are all shadow senders you no longer care about.
How do I check my SPF, DKIM, and DMARC records?
Any DNS lookup tool shows the records. The simplest check is to send an email to a Gmail address, open the message, click the three-dot menu, and choose Show Original. Gmail prints the SPF, DKIM, and DMARC result for that message. For continuous monitoring, use a DMARC aggregator that parses your rua reports into a dashboard. Most paid tools in the space do this for a monthly fee.
What happens if an email fails DMARC?
The receiving server applies whatever policy your DMARC record specifies. If the policy is p=none, the message is still delivered but logged in the aggregate report. If the policy is p=quarantine, the message is routed to the spam folder. If the policy is p=reject, the message is bounced and never seen by the recipient. The sender may or may not get a bounce notification depending on how the provider handles rejections.
Can I use SPF, DKIM, and DMARC with multiple email services?
Yes, and most companies do. Each service publishes its own SPF include: and its own DKIM selector. Your SPF record aggregates the includes, each DKIM selector gets its own TXT record at selector._domainkey, and one DMARC record covers the whole domain. The main constraint is the ten-DNS-lookup limit on SPF, which forces senders with many vendors to flatten their record or use a hosted SPF service.
Do SPF, DKIM, and DMARC stop phishing entirely?
No. They stop attackers from spoofing your exact domain, which closes one major attack vector. They do not stop lookalike domain attacks (yourc0mpany.com instead of yourcompany.com), compromised legitimate accounts, or social engineering through unrelated channels. Email authentication is one layer of a security program, not the whole program.
Why did Google and Yahoo change the rules in 2024?
Both providers announced the change in October 2023 and enforced it in February 2024 to reduce the volume of spam and phishing hitting their users. The rules formalized what deliverability engineers had been recommending for a decade: authentication, alignment, one-click unsubscribe, and a cap on spam complaints. The change moved authentication from a best practice to a hard requirement for anyone sending at scale.