What is / Full version
SPF, DKIM, and DMARC together
SPF authorizes hosts. DKIM signs messages. DMARC ties the visible From domain to those results and publishes policy plus reporting addresses.
Short answerAll topics in What is
Order of evaluation
Receivers typically evaluate SPF during SMTP and DKIM after the message is available. DMARC consumes both results plus the header From domain. A DMARC pass requires alignment with at least one passing mechanism.
None of the three replaces the others. SPF does not prove the message was signed. DKIM does not prove the envelope domain was authorized. DMARC does not publish SPF or DKIM keys.
Policy progression
RFC 7489 expects many domains to begin with p=none while collecting aggregate reports, then move to quarantine or reject when operators understand their legitimate senders.
Google's sender guidelines require authentication for mail to personal Gmail accounts and list additional requirements for bulk senders. Those guidelines are Google's delivery policy, not part of the RFCs.
Failure modes
SPF can pass while DKIM fails if the message was not signed. DKIM can pass while SPF fails if the envelope domain is not authorized. DMARC fails unless at least one aligned mechanism passes.
Receivers may still deliver mail that fails DMARC when policy is none. quarantine and reject ask receivers to treat failures more harshly once the domain owner is confident legitimate mail aligns.