Three DNS records decide whether mailbox providers trust email from your domain. What each one is for, what the record looks like, and the order to add them.
Why three records exist at all
Email was designed in a time when anyone could put any address in the From line, and the receiving server would believe it. That is still technically true. Spoofing a sender is trivial, which is why phishing works, and why mailbox providers stopped trusting the From line and started asking the domain itself to vouch for the message.
SPF, DKIM and DMARC are the three ways a domain does that. They are all plain text records published in your DNS, the same place your website's address lives, so anyone receiving a message from you can look them up. SPF says which servers may send for the domain. DKIM proves the message was not altered after a server you control signed it. DMARC ties the two to the visible From address and tells receivers what to do when they fail. Since 2024 Google and Yahoo have required all three from anyone sending bulk mail, and most other providers lean the same way.
You set them up once, for each domain or subdomain you send from. After that they work silently, and the only time you touch them again is when you add a new sending service.
SPF: who is allowed to send for you
SPF stands for Sender Policy Framework. It is a single TXT record at the root of your sending domain that lists the mail servers permitted to send on its behalf. When a message arrives, the receiving server looks at the domain in the technical return address, fetches that record, and checks whether the server that delivered the message is on the list.
The record looks like v=spf1 include:sender.example ~all. The include parts name your sending services, such as your email marketing platform and your office email. The ending says what to do with everything else: ~all is a soft fail, which is the usual recommendation, and -all is a hard fail.
- One record per domain. Two SPF records is an error that fails everything. Add new services to the existing record.
- Ten lookups maximum. Each include can trigger more lookups, and the standard caps the total at ten. Too many services in one record and SPF silently breaks.
- SPF alone is not enough. It checks the hidden return address, not the From line people see, and it breaks when a message is forwarded. That is what the other two records are for.
DKIM: proof the message was not changed
DKIM stands for DomainKeys Identified Mail. Your sending service holds a private key. When it sends a message, it computes a signature over the headers and body and adds it to the message. You publish the matching public key in DNS, and the receiving server uses it to check the signature. If it matches, the message came from a server holding your key and nothing in the signed parts was altered along the way.
The record is a TXT or CNAME entry at a name like selector._domainkey.yourdomain.com. The selector is just a label, so you can have several keys for several services. Your email platform generates the key pair and tells you the exact record to publish; you never handle the private key yourself.
DKIM survives forwarding, which SPF does not, and it is the signal mailbox providers weight most heavily when building a domain's reputation. If you could only have one of the three, this would be it. Brainito generates DKIM records for your domain during verification and sends from your domain only once they resolve, so an unsigned message never goes out under your name.
DMARC: the policy that ties them together
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It does two jobs. First, it requires that the domain which passed SPF or DKIM lines up with the domain in the From line people actually see, which closes the gap that lets a spoofer pass SPF on their own domain while displaying yours. Second, it tells receivers what to do with mail that fails: nothing, quarantine it, or reject it. It also gives them an address to send reports to.
The record is a TXT entry at _dmarc.yourdomain.com and the minimal version is v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. The policy p=none means monitor only: nothing is blocked, but you receive daily reports showing which servers are sending as your domain and whether they pass. That is the right place to start.
After a few weeks of reports, when every legitimate source passes, move to p=quarantine, then to p=reject. At reject, a message that fails authentication while claiming to be from you is refused outright, which protects your customers from phishing in your name. The reports are XML and hard to read by hand, so most people run them through a free or low-cost report viewer.
The order to set them up
- Pick the sending domain. Many businesses send marketing from a subdomain, such as news.yourbrand.com, so that a campaign problem never touches the reputation of the root domain used for invoices and support.
- Add DKIM first. Your platform gives you the record. Publish it, wait for DNS to update, confirm it resolves.
- Add or update SPF. If a record exists, add the new include to it. If not, create one with your services and ~all.
- Add DMARC at p=none. Collect reports for a few weeks and fix any legitimate sender that fails.
- Tighten DMARC. Quarantine, then reject, once everything passes.
- Send a test. Most mailbox providers let you view the original message with its authentication results. Look for pass on all three.
Expect DNS changes to take minutes to a few hours to propagate. Nothing here requires a developer; it requires access to your registrar or DNS host and a careful copy and paste.
What this looks like in practice
In Brainito, you add a domain under sending settings and the app lists the records to publish, checks them on a timer, and marks the domain verified when they resolve. Until then you can send from a Brainito address at up to 100 emails a day, which is enough to design and test your first campaign. Once verified, every campaign and every automated email is signed with your DKIM key and sent from your own address, on every plan including the free one.
The records are not a growth tactic and they will not improve a campaign that people do not want. What they do is make sure the mail you send is credited to you, that nobody else can send as you, and that the reputation you earn by sending well accrues to a domain you own. For a small business that plans to be around in five years, that is the point.
