Get in touch
Email security

SPF, DKIM and DMARC: a guide for businesses

Published:

Short answer: SPF, DKIM and DMARC are three records in your domain's DNS that prove an email really comes from you. Without them, anyone can send messages that look like yours, and the large providers doubt even your genuine emails. DMARC became an official IETF standard in May 2026, so many guides in circulation are now out of date.

What each one does

The three records at a glance
RecordWhat it answersWhere it lives in DNSCommon mistake
SPFWhich servers may send email for the domainTXT on the domain itselfTwo SPF records, or more than 10 DNS lookups
DKIMThe message was signed by the domain and was not altered in transitselector._domainkey recordsSigning was not switched on after creating the records
DMARCWhat the recipient should do when the above fail, and where to send reportsTXT at _dmarcLeaving it at p=none forever

DMARC passes when SPF or DKIM passes and the checked domain matches the domain in the From field.

Why they are now required

Google and Yahoo applied strict rules from February 2024. Microsoft followed for Outlook.com, Hotmail.com and Live.com addresses from 5 May 2025. For anyone sending more than 5,000 messages a day to consumer addresses, SPF, DKIM and DMARC (at least p=none) are required, with domain alignment. Google asks all senders for at least SPF or DKIM.

A small business rarely exceeds 5,000 messages. The benefit, however, is not only delivery: DMARC with a strict policy prevents your exact domain from being used for forged messages, such as payment scams aimed at your customers or suppliers.

What changed in 2026

In May 2026 the IETF published RFC 9989, 9990 and 9991, which replace RFC 7489 from 2015. DMARC became a Proposed Standard on the standards track rather than just an informational document. Existing records keep working and still start with v=DMARC1.

  • The pct tag, which let you apply the policy to a percentage of messages, is removed from the new standard. Do not use it in your new records.
  • New tags are added (for example np for non-existent subdomains and t for test mode).
  • The "organizational domain" is now determined by walking the DNS tree instead of using the Public Suffix List.

Note: Microsoft's DMARC guide still refers to RFC 7489 and pct. For most businesses the practical advice is simple: write a record with v=DMARC1, p and rua, and move forward gradually, as below.

Step by step in Microsoft 365

  1. List everyone who sends email with your domain: Microsoft 365, your CRM, your newsletter, your website (forms), your accounting software, external providers. Whatever you do not list will fail later.
  2. SPF: a single TXT record. For Microsoft 365 the basic form is v=spf1 include:spf.protection.outlook.com -all, and you add your other senders inside it. Keep DNS lookups under 10.
  3. DKIM: in the Microsoft Defender portal, under email authentication settings, create keys for the domain, publish the two CNAME records selector1 and selector2 with the exact values shown (do not build them by hand), and then switch signing on.
  4. DMARC, first phase: publish at _dmarc the record v=DMARC1; p=none; rua=mailto:dmarc@your-domain.gr, with a shared mailbox for reports. Read the reports every week.
  5. Fix every legitimate sender that fails. When legitimate messages pass consistently, change to p=quarantine and watch. Microsoft recommends reaching p=reject gradually, without rushing.
  6. Domains you own but do not use for email (for example parallel .com or .eu names) should be protected: SPF with -all, no DKIM and DMARC with p=reject. That way nobody can use them for forged messages.

How long the first phase lasts depends on the number of senders. In most small businesses it is a few weeks. This is our own practical estimate, not a rule.

Common mistakes

  • Two SPF records on the same domain. The second one breaks the first.
  • More than 10 DNS lookups in SPF (for example many includes), which leads to failure.
  • Forgotten external senders, such as the newsletter or the CRM, that have no DKIM signature of their own for the domain.
  • DMARC staying at p=none forever. It monitors, but it does not protect.
  • Reports going to a personal mailbox and filling it. Use a shared mailbox or a report-reading service.

How to check your own domain

You can see in a few seconds whether your domain has SPF, DKIM and DMARC and what to fix, with ITHACA's free domain security check.

Frequently asked questions

Do I need DMARC if I send few emails?

The providers' strict rules apply to those sending more than 5,000 messages a day. DMARC, however, also protects a small business, because it prevents your exact domain from being used for forged messages.

What do p=none, quarantine and reject mean?

None only asks for reports and does not affect delivery. Quarantine asks for failing messages to be treated as suspicious (for example sent to junk). Reject asks for them to be rejected. The recipient ultimately decides what to do.

Does DMARC stop phishing?

It stops others from using your exact domain. It does not stop messages from look-alike domains (for example one letter different) or phishing from other domains aimed at you. That is why email filtering and staff training are needed too.

The standard changed in 2026. Do I need to change my record?

Not immediately. Existing records with v=DMARC1 remain valid. For new records avoid the pct tag, which the standard removes.