Short answer: SPF identifies allowed senders, DKIM proves message integrity with a signature, and DMARC requires the visible From domain to align with SPF or DKIM. Passing one check does not make the other two optional.
SPF vs DKIM vs DMARC
| Record | Primary job | What receiving systems evaluate | Common mistake |
|---|---|---|---|
| SPF | Authorize sending sources | Whether the envelope sender's domain permits the sending server | Publishing multiple SPF records or omitting a legitimate sender |
| DKIM | Sign the message | Whether the signature validates against the domain's public key | Publishing the key but never enabling signing |
| DMARC | Require alignment and state policy | Whether SPF or DKIM passes with a domain aligned to the visible From address | Publishing a policy before inventorying every legitimate sender |
What SPF proves
SPF is a DNS TXT policy listing the services allowed to send for a domain. The receiver evaluates it against the message's envelope sender, which is not always the same address a recipient sees in the From field.
Keep one SPF record per domain. When several systems send mail, combine their permitted sources inside that one policy instead of creating competing records. Google and Microsoft both warn that multiple SPF records cause validation problems.
What DKIM proves
DKIM adds a cryptographic signature to each message. The public key lives in DNS under a selector; the sending service keeps the private key and uses it to sign outbound mail.
A DNS record alone is not enough: signing must also be enabled in the mailbox provider. Google recommends 2048-bit keys when the DNS host supports them, while accepting 1024-bit keys where necessary.
What DMARC adds
DMARC connects authentication to the visible identity. It checks whether the domain validated by SPF or DKIM aligns with the domain in the From address, then applies the published policy when alignment fails.
A monitoring policy such as p=none can collect reports before stricter enforcement. Moving to quarantine or reject without understanding every legitimate sender can block mail your organization intended to send.
What large mailbox providers require
Google requires SPF or DKIM for all senders to personal Gmail accounts. Senders above Google's bulk threshold must use SPF, DKIM, and DMARC, align the From domain, support easy unsubscribe for applicable messages, and keep reported spam rates below 0.3%.
Yahoo's published bulk-sender requirements similarly call for SPF, DKIM, a valid DMARC policy, alignment, easy unsubscribe, and spam complaint rates below 0.3%.
A safer setup order
- Inventory every service that sends mail for the domain.
- Publish one SPF policy containing all legitimate sources.
- Generate DKIM keys, publish the public records, and enable signing.
- Publish DMARC in monitoring mode with a reporting destination you control.
- Send test messages and inspect the authentication results.
- Review DMARC reports before tightening enforcement.
- Revalidate whenever a provider, domain, or sending path changes.
How MailSequence handles this
With the Cloudflare nameserver-delegation flow, MailSequence coordinates SPF, DKIM, and DMARC setup and shows nameserver and setup status. Confirm the resulting live records independently before sending. You still own the domain and remain responsible for accounting for every other system that sends from it.
See the MailSequence domain and DNS workflow →
Primary sources
- Google: Email sender guidelines
Authentication, alignment, unsubscribe, spam-rate, and volume-ramp requirements. - Google Workspace: Set up SPF
Single-record guidance and Google Workspace SPF configuration. - Google Workspace: Set up DKIM
Key generation, selectors, signing, and verification. - Microsoft 365: Add DNS records
Microsoft SPF configuration and links to DKIM and DMARC setup. - Yahoo Sender Hub: Sender best practices
Authentication, alignment, unsubscribe, and complaint-rate requirements.