technical · sourced answer

What is Email Authentication: SPF, DKIM, and DMARC Explained

Email authentication is a set of DNS based protocols used to verify the identity of the sender of an email message. It prevents domain spoofing and phishing by allowing receiving mail servers to validate that the sending server is authorized to send mail on behalf of the domain listed in the From header.

Sender Policy Framework (SPF)

SPF is a DNS record that lists all IP addresses and domains authorized to send email for a specific domain. When a server receives a message, it checks the SPF record of the domain found in the Return-Path address. If the sending server IP is not listed in the SPF record, the message may be marked as spam or rejected based on the record's qualifier.

DomainKeys Identified Mail (DKIM)

DKIM provides a cryptographic signature for emails. The sender uses a private key to sign the message headers and body, and the receiver uses a public key published in the domain DNS records to verify the signature. This ensures that the email content has not been tampered with during transit and confirms the domain's ownership of the message.

Domain-based Message Authentication, Reporting, and Conformance (DMARC)

DMARC ties SPF and DKIM together by providing instructions to the receiving server on how to handle messages that fail authentication. It requires alignment between the visible From address and the SPF or DKIM domains. DMARC policies can be set to none (monitor), quarantine (send to spam), or reject (block entirely).

Implementation and Verification

Implementing authentication requires adding TXT records to your DNS provider. Developers should ensure that all third party sending services are included in the SPF record and that DKIM keys are rotated periodically. You can use SendHQ free tools (https://sendhq.cc/tools) to verify that your DNS records are correctly formatted and active.

Questions teams ask

Does SPF replace DKIM?

No. SPF validates the sending server IP, while DKIM validates the message content and origin via cryptography. Both are needed for full authentication.

What happens if DMARC is not configured?

Without DMARC, receiving servers may still use SPF and DKIM, but they have no explicit instruction on whether to reject or quarantine failed messages.

Can multiple SPF records exist for one domain?

No. A domain must have only one SPF record. Multiple authorized senders must be combined into a single TXT record using include mechanisms.

Primary sources