SPF, DKIM and DMARC Explained in Plain English
The Warmuply TeamLast checked: October 2026
If you're getting ready for your first mail merge, someone has probably told you to "check your SPF, DKIM and DMARC". This guide has SPF, DKIM and DMARC explained in plain English, with no IT background needed.
You'll learn what each one does, how they work together, and what they look like in your domain settings. You'll also see what they can't do, which matters just as much when you're trying to stay out of spam.
SPF, DKIM and DMARC explained: what does each one do?
SPF, DKIM and DMARC are three short text records that prove an email really came from your company. Inboxes like Gmail, Outlook and Yahoo look them up when your email arrives.
They live in your DNS, which is the settings area for your domain. Your domain is the part of your email address after the @, such as yourcompany.com. You manage DNS wherever you bought the domain or where it's hosted, called your domain host.
Here's the short version, using a letter as the comparison:
| Record | What it does | Everyday comparison |
|---|---|---|
| SPF | Lists the servers allowed to send email for your domain | The guest list at the door |
| DKIM | Adds a hidden digital signature to each email | A tamper-proof seal on the envelope |
| DMARC | Tells inboxes what to do if an email fails, and sends you reports | Instructions to the doorman |
Why do SPF, DKIM and DMARC matter for a mail merge?
They matter because the big inboxes now expect them. Without them, anyone could pretend to be you, so inboxes treat unproven mail with more suspicion.
Gmail's sender guidelines ask every sender to set up SPF or DKIM. Once you send more than 5,000 messages a day to Gmail accounts, you need SPF, DKIM and DMARC, and your From address has to match the domain that passed SPF or DKIM. Yahoo has the same split between all senders and bulk senders. Microsoft has set similar rules for senders of more than 5,000 emails a day to Outlook.com, Hotmail and Live addresses.
Most mail merges are well under 5,000 a day. Even so, setting up all three is the simplest way to show inboxes that your bulk email is from a real, accountable sender.
What is an SPF record?
An SPF record is a list of the mail servers allowed to send email using your domain. SPF stands for Sender Policy Framework. When an email arrives, the receiving server checks whether it came from a server on your list.
Think of it as the guest list at a door. If the sending server is on the list, it gets in without fuss. If it isn't, the inbox becomes suspicious.
For a domain that only sends through Google Workspace, Google gives this record:
v=spf1 include:_spf.google.com ~all
In plain words:
v=spf1says "this is an SPF record".include:_spf.google.comadds Google's own list of mail servers._spf.google.combelongs to Google, which is why you copy it exactly.~allsays "treat mail from anyone not listed as suspicious". Google recommends this ending.
If you also send from another service, such as a newsletter tool or a help desk, it needs its own include: in the same record. The shape looks like this, where the bracketed part is a placeholder:
v=spf1 include:_spf.google.com include:[your other email service] ~all
Two rules trip people up:
- One SPF record per domain. The SPF standard says a domain must not publish two, and inboxes treat two as an error. Edit the record you have.
- Keep it short. Google says a record can have up to 10
include:tags. The standard caps the total DNS lookups at 10, and going over counts as an error.
Our step-by-step guide shows how to set up SPF for Google Workspace.
What is DKIM?
DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The receiving server uses it to confirm two things: the email came from your domain, and nobody changed it on the way.
It works like a wax seal on a letter. Your mail server holds a private key that stamps the seal. You publish a matching public key in your DNS, so any inbox can check the seal is real.
With Google Workspace, you generate the key in the Google Admin console under Apps > Google Workspace > Gmail > Authenticate email. You then add it to your DNS as a TXT record (a plain-text DNS entry) at this address:
google._domainkey.yourcompany.com
Here, google is the label Google uses by default (called a selector), and _domainkey is the fixed part every DKIM record uses. Google recommends a 2048-bit key if your domain host supports it. After adding the record, you go back to the Admin console and click Start authentication. Google says it can take up to 48 hours to start working.
For the full walkthrough, see our guide on how to turn on DKIM in Google Workspace.
What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells inboxes what to do with email that claims to be from you but fails SPF and DKIM. It also lets you ask for reports on how your mail is doing.
It's the instruction card you give the doorman: "If someone shows up without a seal and isn't on the list, here's what to do."
DMARC adds one more test, called alignment. It isn't enough for an email to pass SPF or DKIM for any domain. The domain that passed has to match the domain in your From address, yourcompany.com.
A simple starting record, added as a TXT record at _dmarc.yourcompany.com, looks like this:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
p=is the policy.nonemeans deliver as normal and just report.quarantinemeans send failing mail to spam.rejectmeans block it.rua=is where daily summary reports go. Google suggests a dedicated mailbox or group, not your personal inbox.
Google recommends starting with p=none, then tightening the policy once you've seen that your real mail passes. It also suggests waiting 48 hours after setting up SPF or DKIM before you add DMARC.
Our guide on how to set up DMARC for Google Workspace covers each setting and when to move past p=none.
How SPF, DKIM and DMARC work together
Three checks on every email
- Deliver
p=none - Spam folder
p=quarantine - Reject
p=reject
Each one covers a gap the others leave. SPF checks the server, DKIM checks the message, and DMARC ties both back to the address your recipient sees.
Say you send a mail merge from you@yourcompany.com to 300 customers. For each email, the receiving inbox runs through roughly these steps:
- SPF: Did this come from a server on yourcompany.com's list? Google's servers are, so yes.
- DKIM: Is the signature valid, and is the email unchanged? Yes.
- DMARC: Did at least one of those passes match yourcompany.com? Yes, so the email is treated as really from you.
If someone else tried to send as you@yourcompany.com from their own server, both checks would fail. Your DMARC policy then tells the inbox what to do with it.
| If an email... | SPF | DKIM | DMARC result |
|---|---|---|---|
| Comes from your Google Workspace with everything set up | Pass | Pass | Pass |
| Comes from a tool you forgot to add to SPF, but it signs with your DKIM | Fail | Pass | Pass (DKIM matches) |
| Is sent by someone pretending to be you | Fail | Fail | Fail: your policy applies |
What the three records look like in your DNS
DNS records for yourcompany.com
3 TXT recordsAll three are TXT records. You add them at your domain host.
| Record | Host / name | Starts with |
|---|---|---|
| SPF | @ (the domain itself, yourcompany.com) | v=spf1 |
| DKIM | google._domainkey | v=DKIM1 |
| DMARC | _dmarc | v=DMARC1 |
Domain hosts differ in how they want the name typed in, so check your host's own help page if you're unsure.
What SPF, DKIM and DMARC can't do
Authentication proves who you are. It doesn't make people want your email, and it doesn't fix what's inside it.
A fully authenticated email can still land in spam if:
- You email people who don't expect it. Old, bought or scraped lists bring bounces and complaints.
- Recipients click "Report spam". Gmail asks senders to keep their spam rate, as shown in Postmaster Tools (Google's free dashboard for senders), below 0.1%, and never to let it reach 0.3%. Yahoo uses the same 0.3% line.
- The email looks like spam. Pushy subject lines, lots of links, attachments and the same template for everyone all raise the risk. Words alone rarely decide it; they matter most because they make people complain.
Our guide to spam trigger words explains which content habits matter and which don't.
The same is true of warmup, which means sending a slowly growing number of everyday emails so inboxes learn to trust a new or quiet address. Warmup builds trust in your inbox. It can't make people want an email they didn't expect.
How Warmuply helps with SPF, DKIM and DMARC
Warmuply checks your domain's SPF, DKIM and DMARC and explains any problems in plain English. If something's missing or wrong, you get the exact text to paste at your domain host.
It also warms up your Google Workspace inbox in the background, shows a daily safe-send number (how many emails the inbox can safely send today), and runs placement tests showing whether your email reaches the inbox, Promotions or spam at Gmail, Outlook and Yahoo. It also sends same-day alerts if your domain lands on a blacklist (a list of senders flagged for spam), with steps to get off it. It works alongside YAMM, Gmail's mail merge, GMass, Google Sheets and Apps Script (Google's built-in scripting tool), so nothing changes in how you send.
Before you hit send
- Run your domain through our free SPF, DKIM and DMARC checker and fix anything marked missing.
- Make sure your domain has only one SPF record, and that it includes every service you send from.
- Check your list: only email people who expect to hear from you, and give them an easy way to opt out.
Start a free 7-day trial: no card needed.
Frequently asked questions
Gmail and Yahoo ask every sender to set up SPF or DKIM, whatever the volume. Gmail requires all three once you send more than 5,000 messages a day to Gmail accounts, and Yahoo requires all three from bulk senders. Setting up all three now costs nothing, takes little time, and means you won’t have to fix it in a hurry later.
Google says SPF and DKIM can each take up to 48 hours to start working after you add the records. Google also suggests waiting 48 hours after setting up SPF or DKIM before you add DMARC, so you can plan on a few days from start to finish.
No. The SPF standard says a domain must not publish more than one SPF record, and inboxes treat two records as an error. If you already have one, edit it and add the new service to the same line instead of creating a second record.
Not if you start with p=none. That policy tells inboxes to deliver mail as normal and only send you reports. Stricter policies, quarantine and reject, can send failing mail to spam or block it, so move to them only once your reports show your real mail passing.
Not fully. You add each record yourself at your domain host. For DKIM, you also generate a key in the Google Admin console and then click Start authentication. A domain checker shows which records are missing.
Sources (7)
- Email sender guidelines (checked October 2026)
- Set up SPF (checked October 2026)
- Set up DKIM (checked October 2026)
- Set up DMARC (checked October 2026)
- Sender Best Practices (Yahoo Sender Hub) (checked October 2026)
- Strengthening Email Ecosystem: Outlook’s New Requirements for High-Volume Senders (checked October 2026)
- RFC 7208: Sender Policy Framework (SPF) (checked October 2026)
Related guides
- SPF Record for Google Workspace: Copy-Paste Setup GuideThe SPF record for Google Workspace is v=spf1 include:_spf.google.com ~all. Add it as a TXT record at your domain host, with the host set to…Read the guide
- DKIM for Google Workspace: How to Turn It On, Step by StepTo turn on DKIM for Google Workspace, sign in to the Admin console as a super admin and go to Apps > Google Workspace >…Read the guide
- DMARC for Google Workspace: Setup Guide (Start at p=none)To set up DMARC for Google Workspace, add a TXT record at your domain host with the host name _dmarc and the value v=DMARC1; p=none…Read the guide
Get your inbox ready before you send.
Warmuply warms up your Google Workspace inbox in the background and shows you how many emails you can safely send each day.
No credit card required.