How to set up SPF, DKIM and DMARC for email deliverability

Since Google and Yahoo's 2024 sender requirements, SPF + DKIM + DMARC is mandatory for any domain sending more than 5,000 emails a month. Here's the full setup.

9 min read advancedUpdated Jun 23, 2026
BI
Reviewed by the editorial team · Jun 23, 2026

Without SPF, DKIM and DMARC correctly configured, your transactional emails land in spam and your marketing emails get throttled. Google and Yahoo enforce this — it's no longer optional.

All three records live in your domain's DNS. Setup takes 15–30 minutes and a few hours of propagation.

Before you start
  • DNS access to your domain (Cloudflare, Namecheap, GoDaddy, etc.)
  • Your sending platform — Google Workspace, Microsoft 365, Resend, Postmark, SendGrid

What each record does

SPF tells receiving mail servers which IPs are allowed to send mail for your domain. DKIM cryptographically signs each message so it can be verified end-to-end. DMARC tells receivers what to do when SPF or DKIM fails, and where to send reports.

All three work together — none is sufficient on its own.

Step by step

  1. 01

    Add the SPF record

    Create a TXT record at the apex (@). Example: 'v=spf1 include:_spf.google.com include:sendgrid.net ~all'. List every legitimate sending service. Only one SPF record per domain.

  2. 02

    Generate and add DKIM keys

    In your sending platform's admin, generate a DKIM key. It gives you a host (like google._domainkey) and a TXT value. Add it as TXT in your DNS.

  3. 03

    Add the DMARC record

    Create a TXT record at _dmarc. Start with monitoring mode: 'v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com'.

  4. 04

    Verify with a checker

    Use mxtoolbox.com or dmarcian.com. All three records should resolve and pass.

  5. 05

    Send a test email

    Send a test to check-auth@verifier.port25.com. You'll get a report back showing SPF, DKIM and DMARC status.

  6. 06

    Move DMARC from p=none to p=quarantine

    After 2–4 weeks of clean reports, upgrade to 'p=quarantine; pct=25;' — sends 25% of failing mail to spam. Gradually raise to 100%.

  7. 07

    Finally, upgrade to p=reject

    Once everything is consistently passing for 30 days, set 'p=reject'. This blocks spoofed mail entirely — the gold standard for deliverability and brand protection.

Key takeaways

  • All three records are mandatory for high-volume senders since the 2024 Google/Yahoo policy.
  • Start DMARC at p=none, monitor reports, then escalate to quarantine and reject.
  • Verify with mxtoolbox.com and a DMARC reporting service like Postmark or dmarcian.

Troubleshooting

DKIM check fails after setup
DNS propagation can take up to 48 hours. Use mxtoolbox.com to confirm the TXT record is visible globally before troubleshooting further.
Multiple SPF records present
Strictly forbidden. Merge into one TXT record with all include: directives combined.

Frequently asked questions

+What's a safe DMARC starting policy?

p=none for the first 2–4 weeks. This monitors without affecting deliverability so you can see who's sending mail under your domain.

+Do I need DMARC if I only use Google Workspace?

Yes. Since February 2024 Google requires DMARC for any domain sending more than 5,000 emails per day to Gmail addresses.

IT & Technical · Done-for-you
Want the boring tech handled?

We set up domains, email, SSL, security and integrations so nothing breaks.

Book a tech call