Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

What is / Full version

SPF, DKIM, and DMARC together

SPF authorizes hosts. DKIM signs messages. DMARC ties the visible From domain to those results and publishes policy plus reporting addresses.

Short answerAll topics in What is

Order of evaluation

Receivers typically evaluate SPF during SMTP and DKIM after the message is available. DMARC consumes both results plus the header From domain. A DMARC pass requires alignment with at least one passing mechanism.

None of the three replaces the others. SPF does not prove the message was signed. DKIM does not prove the envelope domain was authorized. DMARC does not publish SPF or DKIM keys.

Policy progression

RFC 7489 expects many domains to begin with p=none while collecting aggregate reports, then move to quarantine or reject when operators understand their legitimate senders.

Google's sender guidelines require authentication for mail to personal Gmail accounts and list additional requirements for bulk senders. Those guidelines are Google's delivery policy, not part of the RFCs.

Failure modes

SPF can pass while DKIM fails if the message was not signed. DKIM can pass while SPF fails if the envelope domain is not authorized. DMARC fails unless at least one aligned mechanism passes.

Receivers may still deliver mail that fails DMARC when policy is none. quarantine and reject ask receivers to treat failures more harshly once the domain owner is confident legitimate mail aligns.