Pixeldev

Journal/Hosting

SPF, DKIM and DMARC in plain English

Why your invoices land in spam, and the three DNS records that fix it. No acronyms left unexplained.

Liam Hillier. 11 August 2026. 6 minute read.

A plumbing business rang me last year because their invoices were going to spam. Not some of them. Nearly all of them. Their accounting software sent invoices “from” their email address, but nothing in their domain’s settings said it was allowed to. Gmail and Outlook did the sensible thing and assumed it was a forgery.

The fix was three DNS records, about twenty minutes of work, and a week of waiting for things to settle. Here’s what each record does, without the jargon.

SPF: who is allowed to send

SPF stands for Sender Policy Framework. It’s a single line in your DNS that lists the services allowed to send email using your domain. Your email provider, your accounting software, your newsletter tool, your website’s contact form.

When an email arrives claiming to be from you, the receiving server checks that list. If the sender isn’t on it, that’s a mark against the message. Two common mistakes: forgetting to add a service, and having two separate SPF records. You’re only allowed one. If you have two, both are ignored, which is worse than having none.

DKIM: a signature on every email

DKIM stands for DomainKeys Identified Mail. Each sending service signs the emails it sends with a private key. You publish the matching public key in your DNS. The receiving server checks the signature against your public key, and if it matches, it knows two things: the email really came from a service you approved, and nobody changed it on the way.

Each service you send from needs its own DKIM record. Google Workspace gives you one, Microsoft 365 gives you two, Xero and MYOB and most newsletter tools have their own. They’re usually found under a heading like “domain authentication” in that tool’s settings.

DMARC: what to do when the checks fail

DMARC stands for Domain-based Message Authentication, Reporting and Conformance, which is a mouthful for a simple idea. It tells receiving servers what to do with email that fails SPF and DKIM, and where to send reports about it.

It has three settings:

  1. none: deliver it anyway, but send me reports. Start here.
  2. quarantine: put failing email in spam.
  3. reject: refuse it outright.

Start on none for two or three weeks and read the reports. They’ll show you every service sending as your domain, including the ones you forgot about. For the plumber it turned out their old website, which they thought was switched off, was still sending booking confirmations from a forgotten server. Once everything legitimate is passing, move to quarantine, then reject.

The order I do it in

  1. List every service that sends email as your domain. Ask whoever handles accounts, marketing and the website.
  2. Set up DKIM for each one, using that service’s instructions.
  3. Write one SPF record that includes all of them.
  4. Add a DMARC record set to none, with reports going to an address someone actually checks.
  5. Read the reports for a few weeks, fix anything failing, then tighten the policy.

For the plumber, the finished setup was one SPF record covering Microsoft 365 and their accounting software, three DKIM records, and a DMARC record that moved to quarantine after a month. Invoices started landing in inboxes the same week. Their bookkeeper told me overdue invoices dropped noticeably, which makes sense: it’s hard to pay a bill you never saw.

Since early 2024, Google and Yahoo have required all three for anyone sending in bulk, and they’ve become much stricter with small senders too. If you send invoices, quotes or booking confirmations, this isn’t optional any more.

If you’re not sure what your domain has set up, send me the domain name. I’ll check it and tell you what’s missing.

Liam Hillier’s monogram, LH, on Pixeldev green

Liam Hillier

Software, AI and integrations for businesses that have outgrown their spreadsheets. More about Liam.

Previous

Buy or build? A simple test for custom software

Next

Human in the loop: where AI automation should stop and ask