Tagged “spf”
70 articles, page 1 of 2
How to reach DMARC p=reject without breaking email
The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.
Read more
DMARC Alignment Pitfalls with Load Balancer IP Rotation
Load balancer IP rotation can cause DMARC alignment issues, impacting email deliverability, proper management is key to maintaining alignment
Read more
DMARC, SPF, and DKIM for Multi-Brand Companies
Multi-brand companies can improve email deliverability with DMARC, SPF, DKIM, preventing spam and phishing, and protecting their reputation. Proper implementation is crucial for seamless communication across brands
Read more
ARC: Authenticated Received Chain explained
Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.
Read more
How to add DMARC, SPF and DKIM records on Azure DNS
An Azure DNS-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM, covering record sets, the @ apex, TXT chunking, the CLI add-record trap, Alias records and why delegation must be set at the registrar.
Read more
How to add DMARC, SPF and DKIM records on Cloudflare
A precise, Cloudflare-specific walkthrough of publishing TXT and CNAME records for DMARC, SPF and DKIM in the Cloudflare DNS editor, with the real gotchas: root versus host name, the orange-cloud proxy, automatic TXT chunking, CNAME flattening at the apex, TTL on Auto, and Email Routing conflicts.
Read more
How to add DMARC, SPF and DKIM records on DigitalOcean
A DigitalOcean-specific walkthrough for publishing DMARC, SPF and DKIM as TXT and CNAME records in the DigitalOcean DNS editor, covering the root-vs-host hostname convention, the no-auto-chunking DKIM trap, apex CNAME rules and TTL.
Read more
Automatic SPF flattening: staying under ten lookups without thinking about it
SPF has a hard limit baked into the specification: a receiving server is allowed to perform at most ten DNS lookups while evaluating your record.
Read more
DKIM alignment and forwarding
A valid DKIM signature is not the same as DKIM alignment. This guide explains how alignment is evaluated, why DKIM is the one signal that survives forwarding while SPF cannot, and exactly how relays and mailing lists affect it.
Read more
How to add DMARC, SPF and DKIM records on Gandi
A precise, Gandi-specific walkthrough for publishing DMARC, SPF and DKIM in the Gandi LiveDNS editor, covering the root vs host name convention, TXT quoting and chunking, CNAME trailing dots and TTL.
Read more
How to add DMARC, SPF and DKIM records on GoDaddy
A precise, GoDaddy-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the GoDaddy DNS editor, covering root versus host names, TXT chunking, CNAME rules and TTL.
Read more
How to add DMARC, SPF and DKIM records on Google Cloud DNS
A precise, Google Cloud DNS-specific walkthrough for publishing TXT and CNAME records for DMARC, SPF and DKIM, including the gotchas that silently break authentication: public versus private managed zones, console versus gcloud TXT quoting, trailing dots on CNAME targets, 255-byte chunking and a TTL strategy for a safe staged rollout to p=reject.
Read more
Email authentication explained for beginners
Email was designed in an era when everyone on the network trusted everyone else, so it shipped with no built-in way to prove who actually sent a message.
Read more
SPF PermError: when your SPF silently stops working
SPF breaks quietly. Cross the 10 DNS-lookup limit and your record returns PermError, fails open, and stops protecting your domain. Here is how to count, fix and flatten it safely.
Read more
How to add DMARC, SPF and DKIM records on IONOS
A precise, IONOS-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the IONOS DNS editor, covering the root-versus-host gotcha, TXT chunking, CNAME flattening, TTL and a safe sequence to p=reject.
Read more
DMARC alignment explained, with examples
A message can pass SPF and verify DKIM yet still fail DMARC. The reason is alignment. This guide explains SPF and DKIM alignment, relaxed versus strict mode, and the exact DMARC pass rule, with five worked examples of messages that pass and fail.
Read more
How to add DMARC, SPF and DKIM records on Namecheap
A precise, Namecheap-specific walkthrough for adding DMARC, SPF and DKIM records in the Advanced DNS editor, covering the host-field gotchas, TXT chunking, CNAME targets, TTL and the safe path from p=none to p=reject.
Read more
The five DNS records that protect your email
Email was designed in an era of trust. The original protocol, SMTP, lets any server on the internet claim to send mail as anyone.
Read more
How to add DMARC, SPF and DKIM records on OVH
A precise, OVH-specific walkthrough for adding SPF, DKIM and DMARC records in the OVH DNS zone editor, covering the apex naming rule, TXT chunking for long DKIM keys, CNAME trailing dots and TTL behaviour.
Read more
Why email forwarding breaks SPF and DKIM
Email almost never travels in a straight line from sender to recipient. It gets redirected by university and corporate aliases, fanned out by mailing lists, scrubbed by security gateways, and quietly relayed by.
Read more
Reading your first DMARC aggregate report
A field-by-field walkthrough of a DMARC aggregate (RUA) XML report: metadata, source IPs, disposition, SPF and DKIM results, alignment, and spotting spoofers.
Read more
Protecting parked and no-mail domains
Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.
Read more
How to add DMARC, SPF and DKIM records on AWS Route 53
A precise, Route 53-specific walkthrough for publishing SPF, DKIM and DMARC: empty Record name versus host names, TXT quoting and 255-character chunking, why DKIM CNAMEs must never become Alias records, and TTL strategy for a safe staged path to p=reject.
Read more
DMARC for Google Workspace
A new Google Workspace domain ships with no DKIM signing, an SPF record you must add yourself, and no DMARC policy at all. This guide walks the exact order to fix that: get SPF right under the 10-lookup limit, switch on DKIM in the Admin console, then ratchet DMARC from monitoring to full reject without breaking a single legitimate message.
Read more
How to add DMARC, SPF and DKIM records on Squarespace
A precise, Squarespace-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Squarespace DNS editor, including the gotchas that actually break setups: the doubled-domain Host field, TXT chunking, CNAME-at-apex, SPF flattening and TTL.
Read more
DMARC for Microsoft 365
A practical, ordered guide to email authentication on Microsoft 365: build a complete SPF record for Exchange Online, enable DKIM signing with Microsoft's two selector CNAMEs, and walk DMARC safely from p=none through quarantine to p=reject without breaking your mail.
Read more
How to add DMARC, SPF and DKIM records on Wix
A precise, Wix-specific walkthrough of adding TXT and CNAME records for DMARC, SPF and DKIM in the Wix DNS editor, covering the real gotchas: relative host names, long-TXT chunking, CNAME targets without a trailing dot, the one-SPF-record rule and TTL during testing.
Read more
The DMARC record explained, tag by tag
A plain-English reference to every tag in a DMARC record: v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf and ri. What each one does, the exact syntax it expects and the sensible default to reach for.
Read more
How email spoofing actually works
Email spoofing takes no password and no exploit: SMTP simply trusts whatever the sender types into the From field. This guide traces the mechanism from the raw SMTP conversation, through the crucial split between the envelope-from used for delivery and the header-from a human reads, to the three layered controls (SPF, DKIM and DMARC alignment) that finally make forging your domain fail.
Read more
How to fix SPF PermError
SPF PermError means a receiver tried to evaluate your SPF record and gave up, so SPF stops counting towards DMARC. This guide diagnoses PermError, TempError and the ten-lookup limit, then walks through a step by step repair process.
Read more
Why forwarding breaks email authentication
Forwarding almost always breaks SPF and sometimes breaks DKIM too. Here is what survives a forwarding hop, why DKIM is the mechanism that carries your authentication through, how DMARC's one-aligned-pass rule copes, and where ARC rescues mailing-list mail.
Read more
DMARC vs SPF vs DKIM: how they fit together
SPF, DKIM and DMARC are named together so often that they blur into one thing. They are not. This is a clear comparison of what each record actually proves, why SPF and DKIM are blind to the From line your recipients trust, and how DMARC ties them together with alignment and policy.
Read more
One-click unsubscribe: the List-Unsubscribe requirement
Google, Yahoo and Microsoft now require working one-click unsubscribe on bulk mail. Here is what the List-Unsubscribe and List-Unsubscribe-Post headers are, how RFC 8058 one-click actually works on the wire, how to implement it correctly, and why it sits alongside SPF, DKIM and DMARC on the same deliverability checklist.
Read more
PCI DSS 4.0, cyber-insurance and email authentication
PCI DSS 4.0 Requirement 5.4.1 and cyber-insurance questionnaires now treat anti-phishing as a measurable control. Here is exactly how that intersects with DMARC, SPF and DKIM, what counts as evidence, and how to reach enforcement without breaking your own mail.
Read more
Email authentication for ActiveCampaign: SPF, DKIM and DMARC
An ActiveCampaign-specific guide to email authentication: the exact SPF include, CNAME-based DKIM, the custom return-path that aligns SPF, and a staged path to DMARC p=reject without breaking your campaigns or automations.
Read more
Publishing DMARC, SPF and DKIM on common DNS hosts
Exact steps to publish SPF, DMARC and DKIM on Cloudflare, GoDaddy, Namecheap and AWS Route 53, plus the two gotchas that break most setups: TXT chunking on long DKIM keys and CNAME coexistence at the apex.
Read more
Email authentication for Amazon SES: SPF, DKIM and DMARC
Amazon SES passes SPF and DKIM by default but on amazonses.com, so nothing aligns under DMARC. Here is the exact SES include, Easy DKIM and its CNAME selectors, the custom MAIL FROM that fixes SPF alignment, and the staged path to p=reject.
Read more
Why Gmail, Yahoo and Microsoft now require DMARC
Gmail, Yahoo and Microsoft now require SPF, DKIM and DMARC from bulk senders. Here is what each demands, what "require" really means, and how to comply.
Read more
How sender reputation works
Mailbox providers decide where your mail lands based on sender reputation, a private estimate built from how recipients react to your messages and how cleanly you send. This guide explains domain and IP reputation, the signals that raise and lower them, how to warm up a new sender, and why aligned SPF, DKIM and DMARC are what keep the reputation you build genuinely yours.
Read more
Email authentication for Amazon WorkMail: SPF, DKIM and DMARC
Amazon WorkMail sends through SES, so its defaults quietly fail DMARC alignment. Here is the exact SPF include, the three Easy DKIM CNAMEs, the custom MAIL FROM domain that fixes SPF alignment, and the staged path to p=reject without an outage.
Read more
Email authentication for Brevo: SPF, DKIM and DMARC
A Brevo-specific guide to SPF, DKIM and DMARC: the exact spf.brevo.com include, both DKIM CNAME selectors, why the return-path means DKIM (not SPF) carries DMARC on shared IPs, custom return-path with a dedicated IP, and the staged path from p=none to p=reject without breaking delivery.
Read more
Email authentication for Constant Contact: SPF, DKIM and DMARC
Constant Contact sends your campaigns from its own servers under your brand's From address, so by default SPF and DKIM both align to Constant Contact, not you, and DMARC fails. This Constant Contact-specific guide covers self-authentication, the real ccsend.com DKIM CNAMEs, when SPF and a branded return-path matter, and the safe staged path from p=none to p=reject without losing a campaign.
Read more
The SPF 10-lookup limit, explained
SPF caps how much DNS work a receiver may do when evaluating your record. Go over the 10-lookup limit, or the separate void-lookup limit, and SPF returns a permerror that quietly stops helping your DMARC result. Here is how includes consume the budget, why exceeding it breaks SPF, and how to get safely back under the line.
Read more
SPF ~all vs -all vs ?all
Soft fail, hard fail, neutral and pass-all: what each SPF qualifier on the all mechanism actually instructs receivers to do, how DMARC changes the picture, and which one to publish at each stage of your rollout.
Read more
SPF flattening: what it is and when you need it
SPF flattening replaces lookup-based mechanisms with raw IP ranges to dodge the ten-lookup limit. It works, but a hand-flattened record silently goes stale. Here is what flattening really does, the trade-offs, why doing it by hand is risky, and how hosted flattening stays current automatically.
Read more
Email authentication for Fastmail: SPF, DKIM and DMARC
A Fastmail-specific setup guide: the exact spf.messagingengine.com SPF include, the three fm1/fm2/fm3 DKIM CNAMEs, how return-path and DKIM alignment behave, and the safe path from p=none to p=reject.
Read more
SPF records for common email providers
The correct, current SPF includes for Google Workspace, Microsoft 365, Mailchimp, SendGrid, Amazon SES and more, plus how to combine several providers in one record without breaking the 10-lookup limit.
Read more
Email authentication for Freshdesk: SPF, DKIM and DMARC
A Freshdesk-specific setup guide: the exact SPF include, the fdkim1 and fdkim2 DKIM CNAMEs, why the Return-Path means SPF will not align, and how to reach DMARC enforcement on support email without breaking ticket replies.
Read more