Skip to content
Warmuply

SPF, DKIM and DMARC Explained in Plain English

The Warmuply TeamLast checked: October 2026

If you're getting ready for your first mail merge, someone has probably told you to "check your SPF, DKIM and DMARC". This guide has SPF, DKIM and DMARC explained in plain English, with no IT background needed.

You'll learn what each one does, how they work together, and what they look like in your domain settings. You'll also see what they can't do, which matters just as much when you're trying to stay out of spam.

SPF, DKIM and DMARC explained: what does each one do?

SPF, DKIM and DMARC are three short text records that prove an email really came from your company. Inboxes like Gmail, Outlook and Yahoo look them up when your email arrives.

They live in your DNS, which is the settings area for your domain. Your domain is the part of your email address after the @, such as yourcompany.com. You manage DNS wherever you bought the domain or where it's hosted, called your domain host.

Here's the short version, using a letter as the comparison:

RecordWhat it doesEveryday comparison
SPFLists the servers allowed to send email for your domainThe guest list at the door
DKIMAdds a hidden digital signature to each emailA tamper-proof seal on the envelope
DMARCTells inboxes what to do if an email fails, and sends you reportsInstructions to the doorman

Why do SPF, DKIM and DMARC matter for a mail merge?

They matter because the big inboxes now expect them. Without them, anyone could pretend to be you, so inboxes treat unproven mail with more suspicion.

Gmail's sender guidelines ask every sender to set up SPF or DKIM. Once you send more than 5,000 messages a day to Gmail accounts, you need SPF, DKIM and DMARC, and your From address has to match the domain that passed SPF or DKIM. Yahoo has the same split between all senders and bulk senders. Microsoft has set similar rules for senders of more than 5,000 emails a day to Outlook.com, Hotmail and Live addresses.

Most mail merges are well under 5,000 a day. Even so, setting up all three is the simplest way to show inboxes that your bulk email is from a real, accountable sender.

What is an SPF record?

An SPF record is a list of the mail servers allowed to send email using your domain. SPF stands for Sender Policy Framework. When an email arrives, the receiving server checks whether it came from a server on your list.

Think of it as the guest list at a door. If the sending server is on the list, it gets in without fuss. If it isn't, the inbox becomes suspicious.

For a domain that only sends through Google Workspace, Google gives this record:

v=spf1 include:_spf.google.com ~all

In plain words:

  • v=spf1 says "this is an SPF record".
  • include:_spf.google.com adds Google's own list of mail servers. _spf.google.com belongs to Google, which is why you copy it exactly.
  • ~all says "treat mail from anyone not listed as suspicious". Google recommends this ending.

If you also send from another service, such as a newsletter tool or a help desk, it needs its own include: in the same record. The shape looks like this, where the bracketed part is a placeholder:

v=spf1 include:_spf.google.com include:[your other email service] ~all

Two rules trip people up:

  1. One SPF record per domain. The SPF standard says a domain must not publish two, and inboxes treat two as an error. Edit the record you have.
  2. Keep it short. Google says a record can have up to 10 include: tags. The standard caps the total DNS lookups at 10, and going over counts as an error.

Our step-by-step guide shows how to set up SPF for Google Workspace.

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The receiving server uses it to confirm two things: the email came from your domain, and nobody changed it on the way.

It works like a wax seal on a letter. Your mail server holds a private key that stamps the seal. You publish a matching public key in your DNS, so any inbox can check the seal is real.

With Google Workspace, you generate the key in the Google Admin console under Apps > Google Workspace > Gmail > Authenticate email. You then add it to your DNS as a TXT record (a plain-text DNS entry) at this address:

google._domainkey.yourcompany.com

Here, google is the label Google uses by default (called a selector), and _domainkey is the fixed part every DKIM record uses. Google recommends a 2048-bit key if your domain host supports it. After adding the record, you go back to the Admin console and click Start authentication. Google says it can take up to 48 hours to start working.

For the full walkthrough, see our guide on how to turn on DKIM in Google Workspace.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells inboxes what to do with email that claims to be from you but fails SPF and DKIM. It also lets you ask for reports on how your mail is doing.

It's the instruction card you give the doorman: "If someone shows up without a seal and isn't on the list, here's what to do."

DMARC adds one more test, called alignment. It isn't enough for an email to pass SPF or DKIM for any domain. The domain that passed has to match the domain in your From address, yourcompany.com.

A simple starting record, added as a TXT record at _dmarc.yourcompany.com, looks like this:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com
  • p= is the policy. none means deliver as normal and just report. quarantine means send failing mail to spam. reject means block it.
  • rua= is where daily summary reports go. Google suggests a dedicated mailbox or group, not your personal inbox.

Google recommends starting with p=none, then tightening the policy once you've seen that your real mail passes. It also suggests waiting 48 hours after setting up SPF or DKIM before you add DMARC.

Our guide on how to set up DMARC for Google Workspace covers each setting and when to move past p=none.

How SPF, DKIM and DMARC work together

Three checks on every email

Email fromyou@yourcompany.com

Receiving server (e.g. Gmail)

  1. 1

    SPF:Is this server on yourcompany.com’s approved list?

  2. 2

    DKIM:Is the signature valid and the email unchanged?

  3. 3

    DMARC:Does at least one pass match yourcompany.com? If not, follow the domain’s policy.

  • Deliverp=none
  • Spam folderp=quarantine
  • Rejectp=reject

Passing proves who sent it. It doesn’t decide whether people want it.

Three checks, one question: did this email really come from yourcompany.com?

Each one covers a gap the others leave. SPF checks the server, DKIM checks the message, and DMARC ties both back to the address your recipient sees.

Say you send a mail merge from you@yourcompany.com to 300 customers. For each email, the receiving inbox runs through roughly these steps:

  1. SPF: Did this come from a server on yourcompany.com's list? Google's servers are, so yes.
  2. DKIM: Is the signature valid, and is the email unchanged? Yes.
  3. DMARC: Did at least one of those passes match yourcompany.com? Yes, so the email is treated as really from you.

If someone else tried to send as you@yourcompany.com from their own server, both checks would fail. Your DMARC policy then tells the inbox what to do with it.

If an email...SPFDKIMDMARC result
Comes from your Google Workspace with everything set upPassPassPass
Comes from a tool you forgot to add to SPF, but it signs with your DKIMFailPassPass (DKIM matches)
Is sent by someone pretending to be youFailFailFail: your policy applies

What the three records look like in your DNS

DNS records for yourcompany.com

  • SPF

    Type
    TXT
    Name
    @yourcompany.com itself
    Value
    v=spf1 …
  • DKIM

    Type
    TXT
    Name
    google._domainkey
    Value
    v=DKIM1 …
  • DMARC

    Type
    TXT
    Name
    _dmarc
    Value
    v=DMARC1 …
All three are TXT records, added at your domain host.

All three are TXT records. You add them at your domain host.

RecordHost / nameStarts with
SPF@ (the domain itself, yourcompany.com)v=spf1
DKIMgoogle._domainkeyv=DKIM1
DMARC_dmarcv=DMARC1

Domain hosts differ in how they want the name typed in, so check your host's own help page if you're unsure.

What SPF, DKIM and DMARC can't do

Authentication proves who you are. It doesn't make people want your email, and it doesn't fix what's inside it.

A fully authenticated email can still land in spam if:

  • You email people who don't expect it. Old, bought or scraped lists bring bounces and complaints.
  • Recipients click "Report spam". Gmail asks senders to keep their spam rate, as shown in Postmaster Tools (Google's free dashboard for senders), below 0.1%, and never to let it reach 0.3%. Yahoo uses the same 0.3% line.
  • The email looks like spam. Pushy subject lines, lots of links, attachments and the same template for everyone all raise the risk. Words alone rarely decide it; they matter most because they make people complain.

Our guide to spam trigger words explains which content habits matter and which don't.

The same is true of warmup, which means sending a slowly growing number of everyday emails so inboxes learn to trust a new or quiet address. Warmup builds trust in your inbox. It can't make people want an email they didn't expect.

How Warmuply helps with SPF, DKIM and DMARC

Warmuply checks your domain's SPF, DKIM and DMARC and explains any problems in plain English. If something's missing or wrong, you get the exact text to paste at your domain host.

It also warms up your Google Workspace inbox in the background, shows a daily safe-send number (how many emails the inbox can safely send today), and runs placement tests showing whether your email reaches the inbox, Promotions or spam at Gmail, Outlook and Yahoo. It also sends same-day alerts if your domain lands on a blacklist (a list of senders flagged for spam), with steps to get off it. It works alongside YAMM, Gmail's mail merge, GMass, Google Sheets and Apps Script (Google's built-in scripting tool), so nothing changes in how you send.

Before you hit send

  • Run your domain through our free SPF, DKIM and DMARC checker and fix anything marked missing.
  • Make sure your domain has only one SPF record, and that it includes every service you send from.
  • Check your list: only email people who expect to hear from you, and give them an easy way to opt out.

Start a free 7-day trial: no card needed.

Frequently asked questions

Gmail and Yahoo ask every sender to set up SPF or DKIM, whatever the volume. Gmail requires all three once you send more than 5,000 messages a day to Gmail accounts, and Yahoo requires all three from bulk senders. Setting up all three now costs nothing, takes little time, and means you won’t have to fix it in a hurry later.

Google says SPF and DKIM can each take up to 48 hours to start working after you add the records. Google also suggests waiting 48 hours after setting up SPF or DKIM before you add DMARC, so you can plan on a few days from start to finish.

No. The SPF standard says a domain must not publish more than one SPF record, and inboxes treat two records as an error. If you already have one, edit it and add the new service to the same line instead of creating a second record.

Not if you start with p=none. That policy tells inboxes to deliver mail as normal and only send you reports. Stricter policies, quarantine and reject, can send failing mail to spam or block it, so move to them only once your reports show your real mail passing.

Not fully. You add each record yourself at your domain host. For DKIM, you also generate a key in the Google Admin console and then click Start authentication. A domain checker shows which records are missing.

Sources (7)

Get your inbox ready before you send.

Warmuply warms up your Google Workspace inbox in the background and shows you how many emails you can safely send each day.

Start free for 7 days

No credit card required.

We're launching soon

Get on the waitlist for an exclusive launch discount.

We'll only email you about the launch.