Email Authentication: SPF, DKIM, and DMARC
Email Authentication: SPF, DKIM, and DMARC
Purpose: Email authentication tells mailbox providers your messages are legitimate. Setting it up correctly is one of the highest-impact things you can do for your sender reputation and inbox placement.
Before You Begin
You’ll need access to your domain’s DNS settings, or someone on your team (or your IT provider) who does.
How you connect email in Sure Send affects who owns this step:
- Personal Google or Microsoft connection. If your email is hosted on Google Workspace or Microsoft 365, your domain’s SPF and DKIM are typically already configured as part of your workspace setup. Check with whoever manages your Google Workspace or Microsoft 365 account if you’re not sure.
- SMTP or a custom sending domain. If you’re sending through Team Providers with your own SMTP connection or your own domain, you or your domain admin will need to add the SPF and DKIM records yourself.
- Sure Send’s managed email sending (the built-in deliverability suite). [VERIFY: Confirm the exact setup flow and where in Sure Send the required DNS records for a verified sending domain are displayed, so this section can give a specific navigation path instead of a general description.]
For general background on connecting email to Sure Send, see Connect Your Email: Options for Every Provider.
The Three Authentication Standards
Mailbox providers use three protocols to verify that email is coming from a legitimate sender.
| Protocol | Full Name | What It Does |
|---|---|---|
| SPF | Sender Policy Framework | Lists which mail servers are allowed to send email on behalf of your domain |
| DKIM | DomainKeys Identified Mail | Adds a cryptographic signature to each message so mailbox providers can confirm it wasn’t altered in transit |
| DMARC | Domain-based Message Authentication, Reporting and Conformance | Ties SPF and DKIM together and tells mailbox providers what to do when a message fails authentication |
SPF and DKIM verify the message. DMARC sets the policy for what happens when verification fails, and gives you reporting so you can monitor your authentication health over time.
As of 2026, Gmail and Yahoo require all three for anyone sending in volume (roughly 5,000 messages or more to personal accounts in a 24 hour period), and Gmail requires your DMARC policy’s domain to align with either your SPF or DKIM domain. If you’re sending any meaningful volume of email, all three should be in place regardless of the exact threshold.
Setting Up Authentication
SPF and DKIM: These are DNS records added at your domain registrar (GoDaddy, Namecheap, Google Domains, and similar). If you’re on Google Workspace or Microsoft 365, this is typically already done. For SMTP or custom sending domains, your provider (or Sure Send’s onboarding team, for managed sending) will give you the specific records to add.
DMARC: This is also a DNS record. A free record generator is available at dmarcian.com/dmarc-record-wizard if you need help building the record itself.
Authentication as Sender Identity
Beyond verifying individual messages, your authentication records act as a persistent identity for your sending domain. Mailbox providers track your reputation against your from address and your authentication records together, over time. A domain with clean, consistent authentication builds trust. A domain without it starts every send at a disadvantage.
Using a Subdomain for Bulk Mail
If you’re sending bulk messages like newsletters or drip campaigns, send from a subdomain rather than your primary domain. This keeps the reputation of your marketing mail separate from the reputation of your everyday one-to-one correspondence.
Example: If your primary address is hello@yourdomain.com, send campaigns from a subdomain like hello@news.yourdomain.com instead. If a campaign gets flagged or draws complaints, it won’t drag down deliverability for the emails you send to clients one at a time.
This is a DNS configuration change, and a high-value one if you run regular bulk sends.
Tips
Tip: After setup, use a DMARC reporting tool to monitor results. Reports show you which sources are sending mail on behalf of your domain and flag authentication failures early, before they turn into a deliverability problem.
What’s Next
Once authentication is in place, review Email Compliance and Permission Best Practices to make sure who you’re sending to is on solid ground too.