Guides

SPF, DKIM, and DMARC: The Complete Guide to Email Authentication in 2026

Mailofly Team

Master the three pillars of email authentication: SPF, DKIM, and DMARC. Learn how to configure your DNS records, satisfy Google and Yahoo sender requirements, and keep your emails out of the spam folder.

In 2024 and 2026, Google (Gmail) and Yahoo introduced strict new sender requirements for anyone delivering emails to their users. If your domain lacks proper SPF, DKIM, and DMARC records, your emails will either be flagged with a warning banner, diverted into the spam folder, or rejected outright with a 550 5.7.26 error code.

Email authentication is no longer optional for businesses or developers. In this comprehensive guide, we explain exactly how SPF, DKIM, and DMARC work together, how to format your DNS TXT records correctly, and how to verify your domain in minutes.

The Problem Email Authentication Solves

When the Simple Mail Transfer Protocol (SMTP) was invented in 1982, anyone could send an email with any From: address they wanted. There was zero cryptographic verification. A bad actor could claim to be security@bank.com and recipient mail servers had no way of knowing whether the message was legitimate.

To stop phishing, spoofing, and spam, the internet created three complementary layers of defense:

  1. SPF (Sender Policy Framework): Proves which server IP addresses are permitted to send emails on behalf of your domain.
  2. DKIM (DomainKeys Identified Mail): Proves that the email was cryptographically signed by your domain and has not been modified or tampered with in transit.
  3. DMARC (Domain-based Message Authentication, Reporting, and Conformance): Tells receiving mail servers what to do if SPF or DKIM fails (e.g. reject the email or quarantine it to spam), and sends you daily failure reports.

1. SPF (Sender Policy Framework)

SPF is a single DNS TXT record published at the root of your domain (e.g. yourdomain.com). When an incoming mail server (like Gmail) receives an email from user@yourdomain.com, it looks up your domain's SPF record and checks whether the sending server's IP address matches your authorized list.

Example SPF Record

v=spf1 include:_spf.mailofly.com include:_spf.google.com ~all

Breaking Down the Syntax

  • v=spf1: Declares the version of the SPF specification (must be at the beginning).
  • include:_spf.mailofly.com: Authorizes Mailofly's IP cluster to send on behalf of your domain.
  • include:_spf.google.com: Authorizes Google Workspace / Gmail.
  • ~all (SoftFail): Instructs receivers that any IP not listed should be treated with suspicion (soft fail).
  • -all (HardFail): Instructs receivers to reject emails from any unlisted server.

Warning: The 10-DNS-Lookup RFC Limit: RFC 7208 mandates that evaluating an SPF record must not require more than 10 DNS lookups. If your SPF record exceeds 10 lookups (due to too many nested include: mechanisms), major ISPs will return an SPF PermError and mark your email as unauthenticated.

You can test your SPF syntax and check your lookup count for free using the Mailofly Free SPF Checker Tool.

2. DKIM (DomainKeys Identified Mail)

While SPF authenticates the sending server IP address, DKIM authenticates the message content itself using public-key cryptography (RSA).

How DKIM Works

  1. Your email provider (Mailofly) holds a secret private key.
  2. When you send an email, Mailofly computes a cryptographic hash of the email headers and body, signs it with your private key, and attaches a DKIM-Signature header.
  3. You publish the corresponding public key in your domain's DNS as a TXT or CNAME record under a selector (e.g. mailofly._domainkey.yourdomain.com).
  4. When Gmail receives your message, it retrieves your public key from DNS, verifies the signature, and confirms that the message was genuinely signed by your domain and was not altered by a man-in-the-middle.

2026 Industry Standard: 2048-Bit Keys: Both Google and Yahoo now require 2048-bit DKIM keys. Legacy 1024-bit keys are considered cryptographically weak and may trigger deliverability warnings. Mailofly automatically generates 2048-bit DKIM keys for all custom domains.

Verify your public key with our free DKIM Checker Tool.

3. DMARC (The Enforcer)

Even if you have SPF and DKIM configured, bad actors could still spoof your display name or send unauthenticated emails. DMARC ties SPF and DKIM together and provides domain-level policy control.

How DMARC Works

DMARC introduces the concept of Alignment. For DMARC to pass, the domain in the visible From: header must align with either:

  • The authenticated SPF domain, OR
  • The authenticated DKIM signing domain (d=yourdomain.com).

Example DMARC Record

# Published at _dmarc.yourdomain.com as a TXT record
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@yourdomain.com

DMARC Policy Values (p=)

  • p=none (Monitoring Mode): Receivers take no action on failed emails, but send you aggregate XML reports. Use this when first testing.
  • p=quarantine: Receivers divert failing emails to the recipient's Spam/Junk folder.
  • p=reject (Maximum Protection): Receivers outright block and drop any email that fails authentication.

Validate your DMARC alignment and policy using our free DMARC Checker Tool.

How to Authenticate Your Domain in Mailofly

Setting up SPF, DKIM, and DMARC manually used to take hours. In Mailofly, it takes less than 3 minutes:

  1. Log in to your Mailofly dashboard and go to Domains > Add Domain.
  2. Enter your root domain (e.g. acme.com).
  3. Mailofly automatically generates the exact DNS records needed:
    • 1× SPF TXT record
    • 3× DKIM 2048-bit CNAME records
    • 1× DMARC TXT record
  4. Add these records to your DNS provider (Cloudflare, Namecheap, GoDaddy, Vercel, Route 53).
  5. Click Verify Records. Mailofly's background engine validates propagation and immediately activates your sending identity.

Summary Checklist for 2026 Deliverability

Protocol Record Type Key Requirement Free Testing Tool
SPF TXT @ root Must stay under 10 DNS lookups SPF Checker
DKIM CNAME / TXT selector 2048-bit cryptographic key DKIM Checker
DMARC TXT at _dmarc Policy set to quarantine or reject DMARC Checker

Ready to dispatch transactional emails with guaranteed authentication? Start sending with the Mailofly REST Email API or connect via our SMTP Relay today.

Written by

Mailofly Team

· September 25, 2026

The Mailofly Team is a group of builders, marketers, and automation-focused engineers dedicated to simplifying how businesses communicate through email. With a strong focus on deliverability, scalability, and real-world use cases, the team shares practical insights drawn directly from building and using Mailofly in production environments. Rather than theory, Mailofly content is rooted in execution—covering what actually works in cold outreach, campaign automation, and email infrastructure. From improving inbox placement to designing high-converting templates, the goal is simple: help you send smarter emails that get results. Whether you're a solo founder, a growing startup, or scaling outreach at volume, the Mailofly Team creates guides to help you move faster and avoid common mistakes.

Continue exploring guides and insights from the team.