Table of Contents
Emails landing in spam folders or being rejected outright can cost businesses valuable opportunities — whether it's order confirmations, payment receipts, or customer communications. The correct and sustainable solution is to properly configure SPF, DKIM, and DMARC in your domain's DNS. This guide explains each system with real DNS record examples you can use immediately.
What is SPF and How Does It Work
SPF (Sender Policy Framework) is a DNS standard that declares which IP addresses or servers are authorized to send email on behalf of your domain. When a receiving mail server gets an email, it queries the TXT record of the domain in the From/Return-Path header and compares it against the actual sending IP.
If the sending IP is in the SPF record → SPF pass | If not → SPF fail/softfail, which raises the spam score.
How SPF Works Step by Step
- Sender sends email from IP
203.0.113.10claiming from:[email protected] - Receiving mail server queries DNS:
yourdomain.com TXT - Gets SPF Record:
v=spf1 ip4:203.0.113.0/24 ~all - Checks if
203.0.113.10is in203.0.113.0/24→ ✅ Pass
What is DKIM and How Does It Work
DKIM (DomainKeys Identified Mail) is a digital signature system for email. It works with a Public/Private Key Pair — the sending mail server signs outgoing emails with a Private Key, and receivers verify with the Public Key published in DNS.
The advantage of DKIM is that it also verifies message integrity. If an email is tampered with in transit, the DKIM signature becomes invalid immediately.
DKIM Header Attached to Each Email
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yourdomain.com;
s=mail2026; t=1725854400;
bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
h=From:To:Subject:Date;
b=signature_value_here...
| Field | Meaning |
|---|---|
d= | Domain issuing the DKIM signature |
s= | Selector name (used for DNS lookup) |
bh= | Hash of the email body |
b= | The digital signature itself |
What is DMARC and How Does It Work
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a policy that tells receiving mail servers what to do when an email fails SPF or DKIM, and reports those results back to the domain owner.
DMARC also requires SPF or DKIM results to align with the domain in the From: header — not just pass independently.
Three DMARC Policy Levels
| Policy | Action | Best For |
|---|---|---|
p=none | No action, report only | Initial monitoring |
p=quarantine | Move to Spam/Junk folder | Transition phase |
p=reject | Reject the email entirely | Full enforcement |
SPF vs DKIM vs DMARC Comparison
| Aspect | SPF | DKIM | DMARC |
|---|---|---|---|
| Validates | Sending server IP | Signature + content | Policy + Alignment |
| Protects against | IP Spoofing | Message tampering | Domain spoofing (From:) |
| DNS location | TXT at @ | TXT at selector._domainkey | TXT at _dmarc |
| Email forwarding | May fail | Usually passes | Depends on SPF/DKIM |
| Reporting | None | None | Yes (Aggregate + Forensic) |
How to Configure SPF Record
An SPF record is a TXT record at your root domain (@) that always starts with v=spf1.
Basic Syntax
v=spf1 [mechanism...] [all]
Common SPF Mechanisms
| Mechanism | Meaning | Example |
|---|---|---|
ip4: | Allow IPv4 / subnet | ip4:203.0.113.10 |
ip6: | Allow IPv6 | ip6:2001:db8::/32 |
include: | Pull SPF from another domain | include:_spf.google.com |
a | Allow the domain's A record IP | a |
mx | Allow MX servers | mx |
~all | Softfail — others not permitted (recommended) | ~all |
-all | Hardfail — reject all that don't match | -all |
Common SPF Record Examples
# Using own mail server and Google Workspace
v=spf1 mx include:_spf.google.com ~all
# Direct IP + Gmail
v=spf1 ip4:203.0.113.10 include:_spf.google.com -all
# Using AsiaGB Email
v=spf1 include:spf.asiagb.com ~all
v=spf1 causes an immediate SPF fail. Combine all entries into a single record.
Adding SPF in DirectAdmin
- Login to DirectAdmin → Email Manager → MX Records
- Or go to DNS Management → select your domain
- Add TXT Record: Name =
@or leave blank, Value = your SPF string - Save and wait 0-48 hours for DNS propagation
How to Configure DKIM Record
DKIM requires a Key Pair generated from your mail server. You need to:
- Generate a Private Key + Public Key on your mail server
- Configure the mail server to sign outgoing mail with the Private Key
- Publish the Public Key via a DNS TXT Record
DKIM DNS Record Format
# Record name:
SELECTOR._domainkey.yourdomain.com
# Example with selector "mail2026":
mail2026._domainkey.yourdomain.com
# Value:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...
Generating DKIM Keys with OpenSSL
# Generate Private Key (2048-bit RSA)
openssl genrsa -out dkim_private.pem 2048
# Extract Public Key for DNS
openssl rsa -in dkim_private.pem -pubout -out dkim_public.pem
openssl rsa -in dkim_private.pem -pubout | grep -v "PUBLIC KEY" | tr -d '\n'
How to Configure DMARC Record
DMARC is a TXT record at the _dmarc subdomain of your root domain.
DMARC Record Format
# Record name:
_dmarc.yourdomain.com
# Start with monitor mode:
v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1
# Intermediate (quarantine):
v=DMARC1; p=quarantine; pct=50; rua=mailto:[email protected]
# Full enforcement (reject):
v=DMARC1; p=reject; rua=mailto:[email protected]; adkim=s; aspf=s
DMARC Tags Explained
| Tag | Meaning | Values |
|---|---|---|
p= | Main policy | none / quarantine / reject |
sp= | Subdomain policy | none / quarantine / reject |
pct= | % of emails subject to policy | 0-100 (default: 100) |
rua= | Aggregate report address | mailto:email@domain |
ruf= | Forensic report address | mailto:email@domain |
adkim= | DKIM alignment mode | r (relaxed) / s (strict) |
aspf= | SPF alignment mode | r (relaxed) / s (strict) |
Safe DMARC Rollout Strategy
- Week 1-2:
p=none— receive Aggregate Reports, identify all email sources - Week 3-4:
p=quarantine; pct=10— start enforcing for 10% of messages - Month 2:
p=quarantine; pct=100 - Month 3+:
p=reject— full enforcement
Testing and Verifying Your Setup
After configuration, wait 24-48 hours for DNS propagation before running tests.
Recommended Testing Tools
| Tool | Tests | URL |
|---|---|---|
| MXToolBox | SPF, DKIM, DMARC | mxtoolbox.com/SuperTool |
| mail-tester.com | Overall score + spam score | mail-tester.com |
| DMARC Analyzer | Aggregate Reports | dmarcanalyzer.com |
| Google Admin Toolbox | Google's DNS checker | toolbox.googleapps.com/apps/checkmx |
| nslookup / dig | Local DNS verification | terminal |
Verify via Command Line
# Check SPF
nslookup -type=TXT yourdomain.com
# Check DKIM (selector: mail2026)
nslookup -type=TXT mail2026._domainkey.yourdomain.com
# Check DMARC
nslookup -type=TXT _dmarc.yourdomain.com
# Using dig
dig TXT yourdomain.com +short
dig TXT mail2026._domainkey.yourdomain.com +short
dig TXT _dmarc.yourdomain.com +short
Signs Your Configuration is Working
- Email header shows:
Authentication-Results: ... spf=pass dkim=pass dmarc=pass - mail-tester.com score ≥ 9/10
- MXToolBox shows no errors for SPF, DKIM, DMARC
- DMARC Aggregate Report shows no unknown email sources
Authentication-Results — it should show spf=pass, dkim=pass, dmarc=pass
Summary: Go-Live Checklist
- ✅ SPF TXT record set at @ with only one record
- ✅ DKIM enabled on mail server + Public Key added to DNS
- ✅ DMARC record added at _dmarc.yourdomain.com starting with p=none
- ✅ Waited 24-48 hours for DNS propagation
- ✅ Tested with mail-tester.com and MXToolBox
- ✅ Read DMARC Aggregate Reports after 1 week
- ✅ Gradually increased policy from none → quarantine → reject
Need an Email Hosting service that supports SPF/DKIM/DMARC with premium Spam Filtering? AsiaGB Email Filtering helps you configure everything correctly from day one.