DMARC Engine
Home/Resources
Start here

Email authentication resources

Free tools, definitions, guides and answers: everything to understand and fix your email authentication, in one place.

What this library is for

Email authentication has a small number of moving parts and a lot of folklore around them. This library exists to cut through that.

DMARC, SPF, DKIM, MTA-STS and BIMI are not complicated once someone explains them plainly and shows you exactly which record to publish. The problem is that the guidance online is scattered, often out of date, and written for people who already understand the jargon. Everything here is written for the person who has to actually fix it: a clear definition, a tool to check the current state, and a known-good path from where you are now to a domain that no one can spoof.

The resources fall into a few groups. Free tools tell you what your DNS says right now. Guides and the glossary explain what it should say and why. The requirements and risk pages explain the deadlines and the stakes that make this worth doing. The blog, docs and knowledge base go deeper once you are in the weeds. You do not need to read all of it. The sections below tell you which resource solves which problem.

Each resource, and who it is for

Pick the one that matches the question you have right now.

Free tools

More than 40 checkers and generators covering DMARC, SPF, DKIM, BIMI, MTA-STS and the underlying DNS. Paste a domain and read back exactly what is published: which records exist, whether they parse, how many SPF lookups you are using, what selectors are signing, and where a record is missing or malformed.

Use this when you want a fast, no-signup answer to "what does my domain actually say today" or you need to generate a correct record to publish. Start at the free tools, or get a fuller picture by email through the report and monitoring page.

Setup guides

Step-by-step DNS instructions for publishing each record correctly the first time, written so you can follow them in your registrar or DNS host without guessing. They cover the record syntax, where it goes, common copy-paste mistakes, and how to confirm it has taken effect.

Use this when a tool has told you what is wrong and you are ready to make the change yourself. Open the setup guides.

Glossary

Plain-English definitions of every email-authentication term, from alignment and selectors to p=reject and aggregate reports. Each entry is short, jargon-free, and linked to a tool so you can check the term against your own domain straight away.

Use this when a report, an audit, or a colleague uses a word you are not certain about. Browse the glossary.

Provider requirements

What Google, Yahoo and Microsoft actually require from bulk senders, and what PCI DSS 4.0 expects from organisations handling card data. This is the practical detail behind the deadlines: thresholds, the difference between a recommendation and a hard rule, and what happens to your mail if you ignore them.

Use this when you need to know whether you are obligated to do this, and by when. Read the provider requirements.

How enforcement works

The four-step path from p=none to an enforced p=reject without an email outage: audit what is sending, align SPF and DKIM, move the policy up in stages, and monitor so it stays that way. This is the method, explained so you can see why each step comes in that order.

Use this when you understand the pieces and want to see how they fit into a safe rollout. Start with step one, audit.

Compare options

An honest comparison of free tools, doing it yourself, and a done-for-you hosted service. It lays out what each approach costs in money and time, where each one tends to break, and which suits a single domain versus a large or fast-changing estate.

Use this when you have decided to act and are choosing how to do it. Read the comparison.

Why it matters

The risk explainers connect the technical gap to the real harm: how an unprotected domain turns into invoice and payment fraud, why poor authentication quietly erodes deliverability, and how it leads to a failed audit. Concrete examples, not scare stories.

Use this when you need to explain to a colleague or a budget holder why this is worth doing. Start with invoice fraud.

Blog, docs and knowledge base

The blog covers practical topics around reaching and keeping enforcement. The documentation explains how to set up and run DMARC Engine across all your domains. The knowledge base gives short, direct answers to common setup and troubleshooting questions.

Use this when you want depth on a specific topic, or you are running the platform and need a precise how-to or a quick fix.

How these resources get you to p=reject

The reason any of this matters is a single outcome: a domain published at p=reject, where mailbox providers refuse anything that fails authentication, so no one can send convincing mail in your name. Getting there safely means moving in order, and each resource here maps to one step of that order.

StepThe questionWhere to start
1. See the truthWhat does my domain publish today, and who is sending as me?Free tools and the email report
2. Understand itWhat do these terms mean, and what does correct look like?Glossary and setup guides
3. Justify itWhy now, and what is the risk of not doing it?Requirements and the risk explainers
4. Do it safelyHow do I move to enforcement without breaking mail?How enforcement works and compare options

The order is not optional. Tightening a policy before you know every legitimate sender is the fastest way to block your own invoices and newsletters. That is why the free tools and the email report come first: they show you every source sending as your domain so that, when you do move the policy up, the only mail that gets stopped is the mail you never sent.

Start with a scan, not a guess. A free check reads your live DNS in seconds and tells you which of these resources you actually need next. Most domains have one or two specific gaps, not a rebuild.

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.