How to Set Up SPF, DKIM, and DMARC for Business Email
Publish one SPF record that lists every service sending mail as your domain, turn on DKIM signing in your mail provider and publish the keys it gives you, then add a DMARC record at p=none with a reporting address. Read the reports for two to four weeks, fix the senders you missed, and move DMARC to quarantine and then reject. Gmail and Yahoo have required all three for bulk senders since 2024, and Microsoft's consumer mailboxes followed in 2025.
Every Wednesday. 28,400+ operators. Zero fluff.
✓ Check your inbox — click the confirmation link to complete sign-up.
✓ You're subscribed!
✓ You're already on the list.
If your proposals, invoices, or cold outreach keep landing in spam, check your DNS before you rewrite a single subject line. Mailbox providers decide whether to trust a message mostly on whether your domain proves it sent it. Three records do that proof, and a surprising number of business domains are missing at least one.
Since February 2024, Gmail and Yahoo have required SPF, DKIM, and DMARC from anyone sending more than 5,000 messages a day to their users, and they ask for a spam complaint rate under 0.3%. Microsoft’s Outlook.com, Hotmail, and Live mailboxes added similar rules for high-volume senders in May 2025. You may send far less than 5,000 a day. The checks still apply to you in practice, because small senders without authentication get filtered first.
This takes about an hour. You don’t need to write code. You need access to wherever your domain’s DNS lives and to the admin console of your email provider.
Table of contents
Open Table of contents
- What each record does
- Step 1: Inventory every service that sends as your domain
- Step 2: Check what you have today
- Step 3: Publish one SPF record
- Step 4: Turn on DKIM for each sender
- Step 5: Add DMARC at p=none and read the reports
- Step 6: Move to enforcement
- Tell Claude or ChatGPT to do it
- Verify and keep it healthy
What each record does
- SPF is a list, published in DNS, of the services allowed to send mail as your domain. A receiving server checks the sending server against that list.
- DKIM is a signature your mail provider attaches to every message. The matching public key sits in your DNS, so the receiver can confirm the message wasn’t altered and really came through your provider.
- DMARC tells receivers what to do when SPF and DKIM fail for your domain, and where to send reports about it. It also requires that the domain they authenticate matches the visible From address.
Without DMARC, SPF and DKIM are advisory. With it, you get a report telling you who is sending mail as you, including the sender you forgot about.
Step 1: Inventory every service that sends as your domain
This is the step people skip, and it’s why they break their own email later. Write down everything that sends from your domain:
- Your mailboxes (Microsoft 365, Google Workspace, or whatever GoDaddy provisioned)
- Your email marketing platform
- Your CRM and invoicing tool
- Your website forms and WordPress transactional mail
- Your helpdesk and any scheduling tool
If you run a Microsoft 365 mailbox through GoDaddy, my walkthrough on how GoDaddy email login works now explains why the admin side sits in Microsoft’s portal. That’s where you’ll turn on DKIM.
Step 2: Check what you have today
Open a free lookup tool such as MXToolbox, Google Admin Toolbox’s Check MX, or the DMARC checker from dmarcian, and enter your domain. Note three things:
- Is there exactly one TXT record starting with
v=spf1? Two is a failure, not a backup. - Does your provider show DKIM as signing?
- Is there a TXT record at
_dmarc.yourdomain.com?
Better still, send a test message from your business address to a Gmail account, open it, choose “Show original,” and read the SPF, DKIM, and DMARC lines at the top. Each should say PASS.
Step 3: Publish one SPF record
Add a single TXT record on the root of your domain. It lists each sender with an include:, then ends with a policy.
Common includes:
- Microsoft 365:
include:spf.protection.outlook.com - Google Workspace:
include:_spf.google.com - Your email marketing platform and CRM each publish their own include value in their help docs. Copy it from there rather than from a blog post, mine included.
A typical result looks like v=spf1 include:spf.protection.outlook.com include:your-esp-value ~all.
Two rules that cause most SPF failures. First, one record per domain: merge new senders into the existing line instead of adding a second record. Second, SPF allows 10 DNS lookups in total, and every include: counts, including the ones nested inside it. Go past ten and receivers treat SPF as a permanent error. If you’re near the limit, drop services you no longer use before you add anything.
Use ~all (soft fail) while you’re still discovering senders, and consider -all once your DMARC reports are clean.
Step 4: Turn on DKIM for each sender
DKIM is configured inside each sending service, then published in DNS.
- Microsoft 365: in the Microsoft Defender portal, open the DKIM settings under email authentication, pick your domain, and enable signing. It gives you two CNAME records (
selector1._domainkeyandselector2._domainkey) to add to DNS first. Enabling fails until they’ve propagated, which can take a few hours. - Google Workspace: in the Admin console under Gmail authentication, generate a key for your domain, publish the TXT record it shows, and click Start authentication.
- Everything else: your email marketing platform, CRM, and invoicing tool each have a “domain authentication” or “sending domain” screen that hands you records to paste into DNS.
Do this for every sender from your inventory, not only your mailbox. A marketing platform that signs with its own domain instead of yours will pass DKIM and still fail DMARC alignment.
Step 5: Add DMARC at p=none and read the reports
Create a TXT record named _dmarc with this value:
v=DMARC1; p=none; rua=mailto:[email protected]
p=none changes nothing about delivery. It starts the reports. Raw DMARC reports are XML files that nobody reads, so point rua at a free reporting service instead. Several DMARC monitoring vendors offer a free tier that turns the XML into a list of sending sources with pass and fail counts.
Leave it at p=none for two to four weeks. You’re looking for legitimate senders that fail, such as an old invoicing tool or a forgotten form plugin, and fixing each by adding it to SPF or enabling its DKIM.
Step 6: Move to enforcement
Once your real senders all pass:
- Change to
p=quarantine; pct=25, so a quarter of failing messages go to spam. Watch for a week. - Raise
pctto 100. - Move to
p=reject.
Getting to reject is what stops others from spoofing your domain in phishing emails to your customers, which protects your name as much as your inbox rate.
Tell Claude or ChatGPT to do it
Paste this into either one, with your own details filled in. It saves you reading each provider’s help pages.
I run email for the domain [yourdomain.com]. My mailboxes are on [Microsoft 365 / Google Workspace]. I also send mail from [list your marketing platform, CRM, invoicing tool, website forms]. Give me: (1) the exact SPF TXT record to publish as one merged line, (2) the DKIM setup steps in each service’s admin screen, (3) a starting DMARC record with rua reporting, and (4) a plan to reach p=reject in four steps. Tell me which values I must copy from each vendor’s own documentation instead of trusting you, and count the DNS lookups in the SPF record.
Before you publish anything it gives you, check the include: values against each vendor’s current help page. Models invent plausible-looking include hosts, and a wrong one fails silently.
Verify and keep it healthy
After DNS settles, repeat the Gmail “Show original” test from every sender, not just your mailbox. Send from your CRM, your invoicing tool, and a website form. Each message should show PASS for SPF, DKIM, and DMARC.
Then put a recurring reminder on your calendar to review DMARC reports quarterly. Every time you sign up for a new tool that emails customers as your domain, authenticate it that day. If you’re building a list or sending newsletters, how to build an email list covers the sending side, and the best email marketing services for small business lists platforms that walk you through domain authentication during setup.
Every Wednesday. 28,400+ operators. Zero fluff.
✓ Check your inbox — click the confirmation link to complete sign-up.
✓ You're subscribed!
✓ You're already on the list.
Related posts
How to Build a Productized Service: My Framework
The exact framework I use to turn one-off consulting work into productized services — defined scope, fixed price, repeatable delivery
MarketingLinkedIn Lead Generation: B2B Clients Without Paid Ads
How I use LinkedIn to generate qualified B2B leads without cold ads — profile setup, content that builds trust over time
EntrepreneurshipFounder-Led Sales: Find and Reach the Right Buyer
A practitioner's playbook for founder-led sales: how to identify the real decision-maker, do contact research, and sequence email, phone
Get the AI playbook in your inbox
Every Wednesday. 28,400+ operators. Zero fluff.
Check your inbox.
We sent you a confirmation email — click the link inside to complete your subscription. Check spam if you don't see it within a minute.
You're subscribed.
Welcome — the next edition lands in your inbox soon.
You're already on the list — look for it every Wednesday.