
A correct SPF DKIM DMARC setup is the cheapest, most direct way to stop criminals from sending email that appears to come from your company’s domain. These three DNS records tell Gmail, Outlook, Yahoo and every other receiver which servers may send for you, whether a message was altered, and what to do with mail that fails.
They are also no longer optional for many senders. Google and Yahoo began enforcing rules for bulk senders in February 2024, and Microsoft followed for Outlook.com in 2025. We manage this work as part of our Microsoft 365 and email security services, and this guide follows the same process: what each record does, example records, the traps that break mail, and a safe path to enforcement.
Key takeaways
- SPF lists servers allowed to send for your domain, DKIM signs each message, and DMARC checks that one of them matches the visible From address.
- SPF fails with a permanent error if evaluation needs more than 10 DNS lookups.
- Move DMARC from p=none to quarantine to reject only after reports show every legitimate sender passing with alignment.
- As of October 2026, Gmail, Yahoo and Outlook.com require SPF, DKIM and DMARC for senders above 5,000 messages a day.
- DMARC enforcement blocks exact-domain spoofing used in business email compromise, but not lookalike domains or hijacked mailboxes.
Where this guidance comes from. This guide draws on the IETF standards (RFC 7208, RFC 6376, RFC 8301, RFC 7489 and its 2026 replacement RFC 9989), Google Workspace and Microsoft Learn admin documentation, Yahoo’s sender requirements, Microsoft’s Outlook.com sender announcement, and the FBI IC3 2025 Internet Crime Report. It also reflects our team’s field experience moving business domains to enforcement and investigating email fraud. If you want it done for you, our DMARC setup service handles SPF, DKIM and DMARC and monitors the reports, and you can request it online.
What SPF DKIM DMARC actually do
Email was built with no way to prove who sent a message. Anyone can type your domain into the From line. These standards add that proof in layers.
SPF: which servers may send for you
Sender Policy Framework (RFC 7208) is one TXT record listing the IP addresses and services authorized to send for your domain. SPF checks the hidden envelope sender (Return-Path), not the From address people see, so SPF alone does not stop spoofing.
DKIM: a tamper-evident signature
DomainKeys Identified Mail (RFC 6376) signs each outgoing message with a private key. The public key sits in DNS at selector._domainkey.example.com, and receivers use it to confirm the message was not altered. RFC 8301 (2018) requires RSA keys of at least 1024 bits and says signers should use 2048.
DMARC: alignment, policy and reporting
DMARC passes only when SPF or DKIM passes and that domain matches the visible From domain. It also publishes your policy (none, quarantine or reject) and asks receivers to send reports on every source using your domain. It was documented in RFC 7489 in 2015 and replaced by RFC 9989 in May 2026.
How SPF DKIM DMARC stops spoofing and supports BEC defense
Business email compromise remains one of the costliest crimes reported to the FBI. The IC3 2025 Internet Crime Report lists 24,768 BEC complaints and $3,046,598,558 in reported BEC losses for 2025, up from about $2.77 billion in 2024.
With DMARC at reject, a criminal cannot send a fake wire-change request showing ap@example.com and land it in your vendor’s inbox, because receivers that honor DMARC refuse it. That protects customers, suppliers and your deliverability.
Know the limits. DMARC does nothing about a lookalike domain like examp1e.com, a display name over a free webmail address, or a mailbox taken over with a stolen password. Those need other controls, covered in how business email compromise works and how to stop it.
Example DNS records for example.com
These use the reserved domain example.com. Your real values come from your mail platform’s admin console.
SPF record (TXT at example.com)
v=spf1 ip4:203.0.113.25 include:spf.protection.outlook.com include:mail.example-esp.net -allThis authorizes one office IP, Microsoft 365 and one marketing platform. Google Workspace uses include:_spf.google.com. You may have only one SPF record: RFC 7208 says more than one produces a permanent error, so adding a second v=spf1 record for a new vendor breaks SPF for all your mail.
DKIM record (TXT at selector1._domainkey.example.com)
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...Microsoft 365 uses two CNAME records (selector1 and selector2) pointing to keys Microsoft manages. Google Workspace uses the default selector google and recommends a 2048-bit key when your DNS host supports it.
DMARC record (TXT at _dmarc.example.com)
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comThat is monitor mode. A fully enforced record looks like this:
v=DMARC1; p=reject; sp=reject; adkim=r; aspf=r; rua=mailto:dmarc-reports@example.comThe rua address receives daily XML aggregate reports. Route them to a DMARC reporting tool, not a person’s inbox.
The SPF 10-DNS-lookup limit
RFC 7208 caps the mechanisms that trigger DNS queries at 10. The include, a, mx, ptr and exists mechanisms and the redirect modifier all count, including lookups nested inside each include. Exceed 10 and the receiver returns permerror, which DMARC treats as a fail. The ip4, ip6 and all mechanisms cost nothing.
This is how an SPF DKIM DMARC setup that worked last year starts failing: each new SaaS tool adds an include, and nobody counts. To stay under the limit:
- Remove includes for services you no longer use.
- Drop
ptr. RFC 7208 says it should not be published. - Move bulk and marketing mail to a subdomain such as
news.example.comwith its own SPF record, as Microsoft recommends. - Rely on aligned DKIM for vendors that support it. DMARC needs only one aligned pass.
- Avoid “SPF flattening” into IP lists unless something keeps those lists current.
DMARC alignment: why passing SPF or DKIM is not enough
A marketing platform can pass SPF for its own bounce domain and DKIM for its own signing domain and still fail DMARC, because neither matches example.com in the From line.
Relaxed alignment, the default, accepts any domain with the same organizational domain, so mail.example.com aligns with example.com. Strict mode requires an exact match. Relaxed is right for most businesses.
The fix is usually in the vendor’s settings: authenticate your domain there so it signs as d=example.com, and set a custom return-path if offered. Microsoft asks for alignment with SPF or DKIM, preferably both. Aligned DKIM matters most, because SPF usually fails when mail is forwarded while a valid DKIM signature normally survives.
Not sure what is sending as your domain? We can read your DMARC reports, map every legitimate sender and build the enforcement plan. Request an email authentication review online, or start with our free cyber risk check.
How to move DMARC from p=none to quarantine to reject
A safe SPF DKIM DMARC rollout puts inventory first and enforcement second. Google advises setting up SPF and DKIM at least 48 hours before DMARC, running p=none for at least a week with daily report review, then moving to quarantine gradually. Microsoft gives the same advice: none, then quarantine, then reject.
| Step | What you do | Check before moving on |
|---|---|---|
| 1. Inventory | List every system sending as your domain: mail platform, CRM, billing, payroll, helpdesk, scanners, web forms | Each sender has an owner and an alignment plan |
| 2. SPF and DKIM | One SPF record under 10 lookups; DKIM on the platform and each vendor | Test headers show spf=pass and dkim=pass for your domain |
| 3. Monitor | p=none with rua | Weeks of reports; unknown sources identified |
| 4. Fix alignment | Vendor domain authentication, custom DKIM, subdomains for bulk mail | All legitimate volume passes DMARC |
| 5. Quarantine | p=quarantine | No missing-mail complaints; failures are only spoofing or forwarding |
| 6. Reject | p=reject; sp=reject | Keep reviewing reports; repeat steps 1 to 4 for each new tool |
| 7. Unused domains | v=spf1 -all and p=reject on parked domains | Every domain you own has records |
Reading DMARC reports
Aggregate reports show each sending IP, its volume, and whether SPF and DKIM passed and aligned. Sort sources into three groups: your systems that pass, your systems that fail (fix before enforcing), and sources you do not recognize, which are usually spoofing. Many large receivers do not send ruf failure reports, so do not plan around them.
What RFC 9989 changes
The May 2026 standard removes the pct tag that older guides, including Google’s tutorial, use to quarantine a percentage of mail, because receivers applied partial values inconsistently. It adds t=y, a test flag asking receivers to apply one level below your stated policy, and np for non-existent subdomains. Providers adopt new tags on their own schedule, so confirm support with your reporting tool.
Gmail, Yahoo and Outlook sender requirements as of October 2026
Starting February 1, 2024, Google required every sender to Gmail personal accounts to use SPF or DKIM, valid forward and reverse DNS, TLS, and a Postmaster Tools spam rate below 0.3%. Yahoo’s rules took effect the same month. Microsoft announced Outlook.com requirements on April 2, 2025, then updated them on April 29, 2025 to reject non-compliant high-volume mail from May 5, 2025 with “550; 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level.”
| Senders over 5,000 messages a day | Gmail | Yahoo | Outlook.com |
|---|---|---|---|
| SPF and DKIM | Both required | Both required | Both must pass |
| DMARC | Required; p=none acceptable | At least p=none; DMARC must pass | At least p=none |
| Alignment | From aligned with SPF or DKIM | From aligned with SPF or DKIM | SPF or DKIM, preferably both |
| Unsubscribe | One-click plus visible link | One-click, honored within 2 days | Visible unsubscribe recommended |
| Spam rate | Below 0.3%; aim below 0.1% | Below 0.3% | No number stated |
| Non-compliant mail | May go to spam or be rejected | Enforced since February 2024 | Rejected with 550 5.7.515 |
Even far below 5,000 messages a day, these rules show where providers are heading. Unaligned invoices from a billing platform are already more likely to land in spam.
Where BIMI fits
Brand Indicators for Message Identification (BIMI) lets supporting mail clients show your logo beside authenticated messages. It is a reward for finishing DMARC, not a substitute. Google’s requirements include a DMARC policy of quarantine or reject (not none) applied to 100% of mail, an SVG logo, and a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC). A VMC requires a trademarked logo, and Google notes the trademark process can take 6 to 12 months.
Common SPF DKIM DMARC mistakes
- Two SPF records. This causes a permanent error for every message. Merge them.
- More than 10 lookups. Count nested includes, not just the visible ones.
- Jumping straight to p=reject. Enforcement before inventory sends your own invoices and payroll notices to spam.
- Staying at p=none forever. It meets the bulk sender minimum but still lets spoofed mail through.
- Ignoring alignment. A vendor passing SPF with its own domain does not pass DMARC for yours.
- No one reads the reports. Without
ruareview you are enforcing blind. - Forgetting parked domains and subdomains. Attackers use the domains you are not watching.
Authentication does not stop everything. Train staff to spot lookalike domains and urgent payment requests; see phishing awareness training that reduces clicks.
Doing SPF DKIM DMARC yourself vs hiring help
A business on one mail platform with no outside senders can often reach enforcement in-house. The effort comes from discovery and from vendors you do not control. Cost drivers include the number of domains you own, the number of third-party senders and whether each supports custom DKIM, who controls DNS, and whether you want ongoing report monitoring.
If spoofed messages are already reaching customers, or someone paid a fake invoice, treat it as an incident first. Our business email compromise response guide lists the first steps.
How Honeybadger handles SPF, DKIM and DMARC for you
Our Microsoft 365, SaaS and email security service covers SPF, DKIM and DMARC managed through to enforcement, plus DNS and MX record management, deliverability and blocklist monitoring, impersonation and BEC defense, message header forensics, and spoofing and domain abuse takedown support, in Exchange Online and Google Workspace.
We inventory every sender, fix alignment with each vendor, run the monitor period, and step your domains to reject on a documented schedule so your own mail keeps flowing. Where we already run your DNS through our managed network and infrastructure service, record changes follow the same tested change process. For continuous monitoring and response, our nationwide managed cyber security (MSSP) team can take it on. We are a veteran-owned, veteran-led firm in Casa Grande, Arizona, delivering this work remotely nationwide.
Submit a service request online with your domains and mail platform, or book a consultation online to walk through your DMARC reports. If spoofed mail or a fraudulent payment is happening now, use our urgent intake form.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
Do I need all three of SPF, DKIM and DMARC?
Yes, for any domain that sends business email. SPF and DKIM prove a message came from an authorized system, and DMARC ties those checks to the visible From address and tells receivers what to do on failure. As of October 2026, Gmail, Yahoo and Outlook.com require all three for high-volume senders.
How long does it take to get DMARC to p=reject?
It depends on how many systems send as your domain. Google’s guidance calls for at least one week at p=none with daily report review before quarantine. Organizations with many third-party senders often need several weeks or more to fix every legitimate source.
Will DMARC stop all business email compromise?
No. Enforcement stops mail that forges your exact domain. It does not stop lookalike domains, display-name tricks or a real mailbox that was taken over. You still need multi-factor authentication, payment verification and staff training.
Should my SPF record end in -all or ~all?
DMARC treats both as an SPF fail. Microsoft recommends -all for Microsoft 365 domains, while Google’s setup page recommends ~all. Once DKIM and DMARC are in place, the DMARC policy decides what happens to failing mail.
What changed with DMARC in 2026?
In May 2026 the IETF published RFC 9989, a Standards Track DMARC that obsoletes RFC 7489. It removes the pct tag, adds a t tag for test mode and an np tag for non-existent subdomains. Existing none, quarantine and reject records keep working.
Do I need DMARC on domains that never send email?
Yes. Unused domains are easy to spoof because nobody watches them. Microsoft advises publishing v=spf1 -all and a DMARC record with p=reject on parked domains.
Sources and further reading
- RFC 7208: Sender Policy Framework (SPF) — 10-lookup limit and one-record rule.
- RFC 6376: DKIM Signatures — DKIM signing and selector key records.
- RFC 8301: DKIM Crypto Usage Update — 1024-bit minimum, 2048-bit recommended keys.
- RFC 7489: DMARC (2015) — Original DMARC tags and alignment modes.
- RFC 9989: DMARC (May 2026) — Current standard; pct removed, t and np tags added.
- Google: Email sender guidelines — Gmail sender requirements from February 1, 2024.
- Google Workspace: DMARC rollout — Monitor period and gradual enforcement.
- Google Workspace: Set up BIMI — BIMI DMARC and certificate requirements.
- Yahoo: Sender best practices — Yahoo bulk sender requirements.
- Microsoft: Outlook high-volume sender requirements — 2025 rules and 550 5.7.515 rejection.
- Microsoft Learn: Set up SPF — Microsoft 365 SPF syntax and parked domains.
- Microsoft Learn: Set up DMARC — Subdomains and parked-domain policy.
- FBI IC3: 2025 Internet Crime Report — 2025 BEC complaints and losses.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles