Why the rules changed in 2024-2025
Google published its Sender Guidelines in October 2023 and tightened them in April 2024: any sender dispatching more than 5,000 messages per day to Gmail accounts must have SPF, DKIM and a DMARC record in place. Microsoft aligned Outlook with the same requirements in May 2025. An email rejected with a 550 never reaches the recipient's inbox. The sender receives a bounce; the message is lost.
What these three records give you in practice
- Guaranteed deliverability — Gmail and Outlook servers accept the message instead of rejecting it with a 550.
- Protection against spoofing — SPF and DKIM prevent a third party from sending emails in your name from an unauthorized server.
- DMARC reports — the rua record sends you daily reports on which servers sent email under your domain.
- Sender reputation preserved — DMARC alignment at p=quarantine then p=reject protects your domain against phishing campaigns.
- Compliance with major platform requirements — mandatory for Mailchimp, Brevo, SendGrid and most ESPs since 2024.
The three DNS records: prerequisites
SPF, DKIM and DMARC are three separate DNS records published in the sending domain's zone. SPF (TXT on your-domain.com) lists authorized servers. DKIM (TXT on mail._domainkey.your-domain.com) adds a cryptographic signature. DMARC (TXT on _dmarc.your-domain.com) tells receiving servers what to do with emails that fail both checks. DMARC alignment — required since 2025 — means the domain in From must match the domain verified by SPF or DKIM.
Configure SPF, DKIM and DMARC step by step
Publish the SPF record
Create a TXT record at the root of your domain listing authorized sources, for example v=spf1 include:_spf.your-provider.com ~all. Only one SPF record per domain.
Enable and publish the DKIM key
Your mail server or ESP generates a key pair. Publish the public key in a TXT record under the chosen selector, for example mail._domainkey.your-domain.com.
Add the DMARC record with reports
Create a TXT record on _dmarc.your-domain.com. Starting value: v=DMARC1; p=none; rua=mailto:[email protected]. In p=none mode no email is rejected.
Verify sender domain alignment
Send a test email and check received headers for Authentication-Results mentioning spf=pass, dkim=pass and dmarc=pass. Tools like MXToolbox or mail-tester.com allow this check.
Tighten DMARC after two to four weeks of reports
When all legitimate sources pass SPF and DKIM, move to p=quarantine, then to p=reject. With p=reject any failing email is refused with SMTP 550.
Security: moving to p=reject and monitoring reports
The p=reject mode is the final goal: it protects your domain against phishing and meets strict Gmail and Outlook requirements. Verify all sending sources sign with DKIM. Enable the ruf tag for forensic reports.
After configuration: monitor and maintain
SPF, DKIM and DMARC are not one-time settings. A new email provider added without updating SPF immediately triggers alignment failures. Plan a quarterly review to check all active sources.