SPF, DKIM and DMARC: what we configure and why it matters
Getting business email reliably into inboxes depends on three DNS-based authentication mechanisms. With Managed Email we configure and verify all three for you — but it's worth knowing what they do.
- SPF (Sender Policy Framework) publishes which servers are allowed to send mail for your domain. Receiving servers check it to confirm a message came from an authorised source, which stops others sending as you.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing mail. The receiving server verifies the signature against a key in your DNS, proving the message really came from your domain and wasn't tampered with in transit.
- DMARC ties the two together and tells receiving servers what to do with mail that fails the checks — protecting your domain from being spoofed by scammers pretending to be you.
Set up wrongly (or not at all), these are the single biggest reason legitimate business mail gets filtered as spam. We configure them correctly, verify them, and keep them right — so your mail authenticates cleanly and your domain is protected from impersonation. It's done once, properly, by people who do it every day.

0 comments
Sign in with your TDesk account to comment.