SPF, DKIM & DMARC explained: SPF authorises sending hosts using DNS records for the MAIL FROM domain.; DKIM signs message content with a private key and verifies it using a public key in DNS.; DMARC aligns SPF or DKIM results with the visible From address domain and enforces policy.
Image: Email Growth Desk

Deliverability

What SPF, DKIM and DMARC each do

Learn what SPF, DKIM and DMARC check, how alignment works and why authentication does not guarantee inbox placement.

SPF checks whether a sending host is authorised for an SMTP identity. DKIM verifies a signature associated with a signing domain.

DMARC checks whether a passing SPF or DKIM identity aligns with the domain in the visible From address, then lets that domain’s owner request handling for failures. A pass on one check does not mean all three pass.

SPF, DKIM and DMARC: What Each Checks

  • SPFChecks if the sending server is authorised for the SMTP MAIL FROM domain (envelope sender).
  • DKIMVerifies a digital signature on message headers and body, proving the signing domain’s authorisation.
  • DMARCEnsures SPF or DKIM alignment with the visible From address domain; enforces policy for failures.

SPF: the SMTP identity

A domain owner publishes an SPF record naming authorised hosts or services. Receivers check the connecting server against the SMTP MAIL FROM domain and may also check HELO.

These identities can differ from the From address shown to a reader. DMARC’s SPF alignment uses the MAIL FROM identity; a separate HELO pass should not be mistaken for aligned DMARC authentication.

A third-party platform may pass SPF for its own envelope domain while the business’s visible From domain remains unaligned. Confirm the actual sending route and the provider’s setup instructions before changing a DNS record.

DKIM: the signing domain

A sending service signs selected headers and the message body. The receiver obtains a public key from the signing domain’s DNS and verifies the signature.

A pass identifies the signing domain in the signature and indicates that the protected material verified. It does not prove that the visible author uses that domain or that the message belongs in the inbox.

For DMARC, inspect the DKIM d= domain, not merely a “DKIM pass” label. Forwarding or mailing-list modifications can sometimes break a signature.

DMARC: alignment with visible From

DMARC uses the domain in the visible From address as its reference. It passes when at least one route both passes authentication and aligns: SPF through its relevant envelope domain, or DKIM through its signing domain.

A domain owner can publish a DMARC policy ranging from requesting no action on authentication failures to requesting altered delivery or rejection. Receiving services retain discretion, and DMARC reports depend on configuration and participating receivers. They are not a complete delivery log.

For example, a hypothetical message visibly From [email protected] could pass DMARC through a valid DKIM signature with d=example.com.au, even if SPF passes only for an unrelated provider domain. If that DKIM signature fails, the unrelated SPF pass does not supply alignment.

Check a sending route

For each campaign or automated service, inspect a received message’s visible From domain, envelope domain, DKIM d= domain and authentication results. Compare them with the intended setup, then confirm any needed DNS change with the provider. Recheck the route after the change.

Authentication success does not establish inbox placement.

Pros and Cons of SPF, DKIM and DMARC

  • SPF: ProsSimple to implement; effective at blocking unauthorised sending servers.
  • SPF: ConsDoes not verify content integrity; can break with email forwarding unless configured correctly.
  • DKIM: ProsProtects message content and headers from tampering; provides strong proof of origin.
  • DKIM: ConsCan fail during forwarding or list processing; requires careful key management.
  • DMARC: ProsEnables domain owners to enforce policies and receive reports on authentication failures.
  • DMARC: ConsRelies on receiving services’ discretion; reports are incomplete and not a full delivery log.

More from Deliverability