What SPF, DKIM, and DMARC Actually Do for Your Mail
What each of the three records actually does, and how to set them up on our mailbox and relay hosting.
What SPF, DKIM, and DMARC Actually Do for Your Mail
If you're sending email from a custom domain โ through our mailbox hosting, SMTP relay, or anywhere else โ these three DNS records are the difference between landing in an inbox and landing in spam (or not arriving at all).
SPF (Sender Policy Framework)
What it does: tells the world which mail servers are allowed to send email claiming to be from your domain. It's a DNS TXT record listing authorized sending IPs/hosts.
Why it matters: without it, any receiving mail server has no way to know whether an email claiming to be from yourdomain.com is legitimate or spoofed โ and modern spam filters treat "no SPF record" as a real red flag, not a neutral non-issue.
What it looks like: something like v=spf1 include:yourmailprovider.com ~all โ the include tells receivers "this provider is authorized to send for me."
DKIM (DomainKeys Identified Mail)
What it does: cryptographically signs every outgoing email with a private key, and publishes the matching public key in your DNS. Receiving servers verify the signature โ proving the email genuinely came from where it claims and wasn't altered in transit.
Why it matters: SPF alone can be bypassed in certain forwarding scenarios; DKIM adds a tamper-proof layer that's much harder to fake. Most serious spam filters weight DKIM-signed mail more favorably than unsigned mail.
What it looks like: a DNS TXT record at a selector-specific subdomain (like mail._domainkey.yourdomain.com) containing a public key. Our mailbox hosting generates this automatically and gives you the exact record to add.
DMARC (Domain-based Message Authentication, Reporting & Conformance)
What it does: tells receiving servers what to do if a mail claiming to be from your domain fails both SPF and DKIM โ reject it, quarantine it (spam folder), or do nothing, plus optionally sends you reports about failures.
Why it matters: SPF and DKIM alone don't stop spoofing on their own โ DMARC is the enforcement layer that actually acts on failures. Domains without DMARC are meaningfully easier to impersonate.
What it looks like: a TXT record at _dmarc.yourdomain.com, e.g. v=DMARC1; p=quarantine; rua=mailto:[email protected].
Setting These Up on Our Mailbox/Relay Hosting
If you're using a custom domain with our mailbox hosting or SMTP relay, your service's management page gives you the exact SPF, DKIM, and MX records to add at your domain registrar/DNS provider โ copy them exactly, since a single typo in a DKIM key breaks verification entirely. Free-tier mailboxes on our shared domain don't need any of this from you โ it's already configured on our end for that domain.
The One-Line Summary
SPF says who can send for you, DKIM proves the mail wasn't tampered with, DMARC decides what happens when something fails both. All three together are what actually gets you real inbox delivery instead of a spam folder โ see our related post on why emails go to spam for more.