TECHNET
TECHNET / Insights / Email

SPF, DKIM and DMARC in plain English

Why legitimate business email lands in spam — and the three DNS records that fix it.

By TECHNET Engineering · 1 Oct 2026 · Email

When your invoice lands in a customer's spam folder, the content is rarely the problem. The receiving server simply cannot prove the message came from you.

The three records

  • SPF lists which servers may send mail for your domain.
  • DKIM adds a cryptographic signature so the message cannot be altered in transit.
  • DMARC tells receivers what to do when SPF/DKIM fail — and sends you reports about abuse.

Start gentle, then tighten

Begin DMARC at p=none (monitor only) and read the reports for a few weeks. Once every legitimate sender passes, move to quarantine, then reject. Add MTA-STS and TLS-RPT to require encrypted delivery between mail servers.

One regional gotcha

Many cloud providers block outbound port 25 by default. Self-hosted mail then needs an authenticated relay with matching SPF and DKIM — otherwise it receives fine but silently fails to send.

Want this for your business? Talk to us — or see the services behind this article.

← Back to Insights