Skip to content
Patrick Webby

Insights

March 10, 2026

SPF, DKIM & DMARC Explained for Small Business Email

Three DNS records stand between your business email and the spam folder. Here's what SPF, DKIM, and DMARC actually do, in plain English.

If your business emails have ever landed in a customer’s spam folder for no obvious reason, there’s a good chance the cause is a missing or misconfigured DNS record — not your email content. Three records in particular do most of the work of proving your email is legitimate: SPF, DKIM, and DMARC.

SPF — who’s allowed to send as you

SPF (Sender Policy Framework) is a DNS record that lists which mail servers are allowed to send email on behalf of your domain. When another mail server receives a message claiming to be from you, it checks your SPF record to see if the sending server is on the approved list.

The common failure mode: a business adds a new tool that sends email on their behalf — a CRM, an invoicing platform, a marketing tool — and never adds it to their SPF record. That mail often gets flagged or rejected.

DKIM — proving the message wasn’t altered

DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outgoing email, generated using a private key that matches a public key published in your DNS. The receiving server checks that signature to confirm the message actually came from your domain and wasn’t tampered with in transit.

Unlike SPF, DKIM is specific to each sending service — if you send email through three different platforms, you typically need three separate DKIM records.

DMARC — telling receivers what to do with failures

DMARC ties SPF and DKIM together and tells receiving mail servers what to do when a message fails those checks — reject it, quarantine it, or let it through — and gives you visibility into who’s sending email using your domain, including potential spoofing attempts. Without a DMARC policy, SPF and DKIM exist but nothing enforces them consistently.

Why this usually gets missed

None of these records are things a business owner sets up once and thinks about again — they get configured (or not) when a domain and mail service are first set up, and then quietly go stale as new tools get added. A new marketing platform starts sending email, nobody updates SPF, and deliverability quietly gets worse over months, not all at once.

We handle this kind of DNS audit and cleanup as part of our email setup & deliverability work — usually the fix is a handful of DNS record changes, not a platform migration.