Email Authentication (SPF, DKIM, DMARC)
Proof of sender, in DNS — three records that decide whether your mail lands, and mandatory table stakes since 2024.
- Term
- SPF / DKIM / DMARC
- Prove
- Mail really comes from the domain
- Live in
- DNS records the receivers check
- Since Feb 2024
- Required by Gmail/Yahoo for bulk senders
Forms & parts of speech
Definition in plain terms
SPF, DKIM, and DMARC are the three DNS-based standards that prove an email genuinely comes from the domain it claims — the identity layer of EMAIL DELIVERABILITY. SPF publishes which servers may send for your domain; DKIM cryptographically signs each message so tampering and forgery show; DMARC ties them together with an alignment requirement and a published policy telling receivers what to do with failures. Since February 2024, Gmail and Yahoo require all three disciplines of bulk senders — authentication stopped being best practice and became the toll for the inbox.
The mechanics
Each layer answers a different forgery. SPF (Sender Policy Framework) is an allowlist in DNS: receivers check the connecting server against the domain's published list — strong against direct impersonation, brittle through forwarding. DKIM (DomainKeys Identified Mail) signs headers and body with a private key whose public half lives in DNS: receivers verify the signature, proving the content left the signer intact and survives forwarding. DMARC closes the hole both leave: it requires alignment — the From: domain the human sees must match the domain SPF or DKIM validated — and publishes policy (none/quarantine/reject) plus reporting addresses, so the domain owner both instructs receivers and learns who is sending as them (the aggregate reports are a standing audit of every ESP, tool, and forgotten system mailing under the brand). The 2024 turn made this marketing infrastructure: Gmail and Yahoo's bulk-sender rules (5,000+ daily messages) require SPF and DKIM, a DMARC record at minimum p=none, From-alignment, one-click unsubscribe, and spam-rate ceilings — with non-compliance priced in deferrals and rejections. The operating disciplines: inventory every legitimate sender before tightening policy (the p=none reporting phase exists to find the marketing-automation tool nobody remembered), move to quarantine/reject deliberately as alignment reaches 100%, and treat authentication as brand protection too — a reject policy is what stops phishers from wearing your domain into your customers' inboxes.
When it matters
Email authentication matters to anyone sending mail that matters — marketing, transactional, sales sequences — because the receivers now demand it and the From: line is a brand asset phishers covet. It matters acutely at ESP migrations, new-tool additions, and subdomain strategies, where alignment quietly breaks. The discipline is staged: publish all three records, read DMARC reports until every legitimate stream aligns, then enforce — and keep the reports flowing, because the senders-as-you list changes every time someone signs a SaaS contract.
Synonyms & antonyms
Synonyms
Antonyms
Origin & history
SPF and DKIM emerged in the 2000s as email's forgery answers, and DMARC (2012, a collaboration of major senders and receivers) tied them into alignment, policy, and reporting; Gmail and Yahoo's February 2024 bulk-sender requirements converted the triad from deliverability craft into mandatory marketing infrastructure.
Etymology: source.
Usage trends
Search interest for this term over the last five years:
Common questions
- What do SPF, DKIM, and DMARC each do?
- SPF publishes which servers may send for the domain; DKIM cryptographically signs messages; DMARC requires the visible From: to align with what passed, publishes failure policy, and reports who sends as you.
- What did the 2024 bulk-sender rules require?
- Gmail and Yahoo require bulk senders (5,000+/day) to have SPF, DKIM, a DMARC record (at least p=none), From-alignment, one-click unsubscribe, and low spam rates — priced in deferrals and rejections since February 2024.
- How should DMARC be rolled out?
- Staged — publish at p=none and read the reports until every legitimate sender aligns, then step to quarantine and reject; the reject policy is also what stops phishers wearing your domain.
Related tools & calculators
Resources & people to follow
- referenceGoogle — email sender guidelines
- referenceDMARC.org — the specification
- referenceRGM analysis — inventory senders at p=none, then enforce; the From: line is a brand asset worth a reject policy
Curated, non-competitor resources verified per term.
Related training
- modulePerformance marketing
Disciplines
Areas of marketing where email authentication (spf, dkim, dmarc) is a core concern:
Sources
- trendsGoogle Trends — "dmarc"