Email authentication

SPF vs DKIM vs DMARC: What's the Difference?

SPF, DKIM and DMARC solve related but different parts of email authentication. A healthy domain email setup commonly uses all three rather than treating them as interchangeable records.

SPF: which systems may send

SPF publishes a policy in DNS describing which sending infrastructure is authorised for a domain. Receivers compare the sending path with that policy. A domain should normally publish one SPF policy rather than multiple competing SPF records.

Advertisement

DKIM: whether a message was signed

DKIM uses a cryptographic signature added by the sending service. The receiving system retrieves a public key from a selector-specific DNS record and uses it to verify the signature.

DMARC: what to do with authentication results

DMARC builds on SPF and DKIM and adds domain alignment plus a published policy. Policies commonly include none, quarantine and reject. DMARC can also provide reporting addresses.

Why all three matter

SPF identifies permitted sending infrastructure, DKIM provides message-level signing, and DMARC tells receivers how aligned authentication should be handled. Correct records do not guarantee inbox placement, but they are important technical signals for authenticated domain email.

Check your domain

Use ZoneCheckr to inspect the live configuration before making changes.

Check Email Security

Still stuck? Get technical help with your domain →