Email Marketing

Email Authentication

Also called SPF DKIM DMARC, sender authentication, bulk sender requirements

DNS records (SPF, DKIM and DMARC) that let receiving mail servers confirm an email genuinely comes from the domain it claims to be from.

Quick facts: Email Authentication

Category
Email Marketing
Also called
SPF DKIM DMARC, sender authentication, bulk sender requirements
Level
Intermediate
Affects
Inbox placement, sender reputation, protection against spoofing and invoice fraud, compliance with Gmail, Yahoo and Microsoft rules
Where to see it
Your domain's DNS settings, your email platform's domain verification page, Gmail "Show original", Google Postmaster Tools, a DMARC report service
In this article4
  1. How email authentication works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

Email authentication is a set of checks, published in your domain’s DNS records, that allow the server receiving a message to check that it really was sent by the domain named on it and was not tampered with in transit. In practice it means three standards working together: SPF, DKIM and DMARC.

How email authentication works

Each standard answers a different question, and each lives as a text record in the Domain Name System (DNS) for your domain.

  • SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. The receiving server checks whether the sending server is on that list. SPF checks the hidden return address, not the “From” address people see, and it allows a maximum of ten DNS lookups.
  • DKIM (DomainKeys Identified Mail) adds a digital signature to each message. Your sending platform signs with a private key; the matching public key sits in your DNS, so the receiver can confirm the message was not changed in transit.
  • DMARC ties the two to the visible “From” domain, a requirement called alignment. It also tells receivers what to do with mail that fails (nothing, quarantine to spam, or reject) and asks them to send you reports.

Consider a typical small business: staff email runs on Microsoft 365, newsletters go out through an email platform, appointment reminders come from a booking system and invoices from accounting software. All four send as the same domain, so all four must be included in SPF and should sign with DKIM using that domain. Miss one and its messages fail DMARC.

Why it matters

Since February 2024, Gmail and Yahoo have required every sender to their users to pass at least SPF or DKIM. Bulk senders, which Google defines as those sending around 5,000 or more messages a day to Gmail addresses, must have SPF, DKIM and a DMARC record, with SPF or DKIM aligned to the From domain, plus one-click unsubscribe and a low spam complaint rate. Microsoft introduced similar requirements for Outlook.com consumer addresses in 2025. These rules apply to UK senders exactly as they do to anyone else, and the details continue to change, so check each provider’s current guidance; this summary was accurate at the time of writing (October 2026).

There is a security reason too. The UK National Cyber Security Centre (NCSC) recommends that organisations set up SPF, DKIM and DMARC to make it harder for criminals to send emails that impersonate them. Fake invoices sent “from” a supplier’s real domain are a common fraud, and a DMARC policy of reject tells receiving servers to refuse mail that forges your exact domain.

Common mistakes

  • Publishing two SPF records instead of one combined record, which makes SPF fail outright.
  • Exceeding the ten-lookup SPF limit by adding every tool you have ever trialled.
  • Letting a marketing platform sign with its own domain rather than yours, so DKIM passes but DMARC alignment fails.
  • Jumping straight to a reject policy before reading reports, and blocking your own invoicing system.
  • Leaving DMARC at “none” indefinitely, which reports on spoofing but stops none of it.

How to act on it

List every service that sends email as your domain, including website contact forms and helpdesk tools. In each one, complete the domain verification steps so it signs with DKIM for your domain. Consider a separate sending domain, such as news.yourbusiness.co.uk, for marketing so its reputation is kept apart from day-to-day mail.

Check the result by sending yourself a message in Gmail and choosing “Show original”: you want SPF, DKIM and DMARC each to say PASS. Then publish a DMARC record at “none” with a reporting address, read the reports for a few weeks, fix anything legitimate that fails, and move to quarantine and then reject.

Authentication is one part of a sound email programme; where it fits with your other channels is part of my digital marketing strategy and consulting work.

Do and do not

Do

  • List every service that sends as your domain before changing records
  • Set each platform to sign DKIM with your own domain
  • Read DMARC reports before tightening the policy

Do not

  • Publish more than one SPF record
  • Jump straight to a reject policy
  • Leave DMARC at none for ever

Questions people ask about this

Does a small business need DMARC?

Gmail and Yahoo strictly require DMARC only from bulk senders; smaller senders must pass SPF or DKIM. I still recommend it for any business that sends from its own domain, because it is the only one of the three standards that tells receivers what to do with mail pretending to be you. A starting record at "none" costs nothing and takes minutes to publish.

Will setting up SPF, DKIM and DMARC stop my emails going to spam?

It removes one common reason for filtering, but it does not guarantee the inbox. Mailbox providers also weigh your sender reputation, complaint rate, bounce rate and how recipients engage. Authentication proves who you are; the rest depends on whether people want your emails.

How long do DNS changes for email authentication take to work?

Most changes are visible within an hour, though some DNS providers take up to a day or two depending on the record's time-to-live setting. Your email platform usually has a "verify" button that confirms when it can see the new records. If verification still fails after a day, check for typos and duplicate records.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.