SPF, DKIM AND DMARC
Email authentication is three separate mechanisms that people treat as one setting, deployed in an order that matters enormously and is almost never explained.
Get the order wrong and you do not see errors. You see silence, because modern mail rejection is deliberately quiet, and silence looks exactly like customers not replying.
This guide covers what each mechanism actually does, the sequence that avoids blocking your own invoices, and how to tell whether any of it is working.
In this guide you will learn:
SMTP trusts the sender. Everything here exists because of that.
What it declares, the ten-lookup limit, and how a correct record fails.
Signing, selectors, key rotation, and why forwarding does not break it.
Alignment, policy, and the instruction that makes the other two matter.
Monitor, read, authorise, tighten. Doing it in any other order blocks your own mail.
What the XML says, which senders are failing, and what to do about each.
The failure with no error message, and how to diagnose it from outside.
Key rotation, new tools, and what changes underneath you.
Chapter 1
SMTP trusts the sender. Everything here exists because of that.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 2
What it declares, the ten-lookup limit, and how a correct record fails.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 3
Signing, selectors, key rotation, and why forwarding does not break it.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 4
Alignment, policy, and the instruction that makes the other two matter.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 5
Monitor, read, authorise, tighten. Doing it in any other order blocks your own mail.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 6
What the XML says, which senders are failing, and what to do about each.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 7
The failure with no error message, and how to diagnose it from outside.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Chapter 8
Key rotation, new tools, and what changes underneath you.
This chapter is not written yet. Drop the prose into
guide-bodies/<body>.html and rebuild.
Check yours
Everything in this guide, checked on your domain in about ten seconds. Free, no account, every finding shown in full.