Email

How to Configure SPF, DKIM and DMARC Correctly
to Stop Emails Going to Spam

Updated: September 9, 2026  ·  12 min read  ·  Category: Email

SPF DKIM DMARC email authentication setup guide

Emails landing in spam folders or being rejected outright can cost businesses valuable opportunities — whether it's order confirmations, payment receipts, or customer communications. The correct and sustainable solution is to properly configure SPF, DKIM, and DMARC in your domain's DNS. This guide explains each system with real DNS record examples you can use immediately.

What is SPF and How Does It Work

SPF (Sender Policy Framework) is a DNS standard that declares which IP addresses or servers are authorized to send email on behalf of your domain. When a receiving mail server gets an email, it queries the TXT record of the domain in the From/Return-Path header and compares it against the actual sending IP.

If the sending IP is in the SPF record → SPF pass | If not → SPF fail/softfail, which raises the spam score.

📌 Why SPF Matters: SPF prevents Email Spoofing — where attackers send emails pretending to be from your domain to deceive customers or conduct phishing attacks.

How SPF Works Step by Step

  1. Sender sends email from IP 203.0.113.10 claiming from: [email protected]
  2. Receiving mail server queries DNS: yourdomain.com TXT
  3. Gets SPF Record: v=spf1 ip4:203.0.113.0/24 ~all
  4. Checks if 203.0.113.10 is in 203.0.113.0/24 → ✅ Pass

What is DKIM and How Does It Work

DKIM (DomainKeys Identified Mail) is a digital signature system for email. It works with a Public/Private Key Pair — the sending mail server signs outgoing emails with a Private Key, and receivers verify with the Public Key published in DNS.

The advantage of DKIM is that it also verifies message integrity. If an email is tampered with in transit, the DKIM signature becomes invalid immediately.

DKIM Header Attached to Each Email

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yourdomain.com;
  s=mail2026; t=1725854400;
  bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
  h=From:To:Subject:Date;
  b=signature_value_here...
FieldMeaning
d=Domain issuing the DKIM signature
s=Selector name (used for DNS lookup)
bh=Hash of the email body
b=The digital signature itself

What is DMARC and How Does It Work

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a policy that tells receiving mail servers what to do when an email fails SPF or DKIM, and reports those results back to the domain owner.

DMARC also requires SPF or DKIM results to align with the domain in the From: header — not just pass independently.

⚠️ Important: DMARC only works effectively when at least SPF or DKIM is already configured. Without either, DMARC will always fail.

Three DMARC Policy Levels

PolicyActionBest For
p=noneNo action, report onlyInitial monitoring
p=quarantineMove to Spam/Junk folderTransition phase
p=rejectReject the email entirelyFull enforcement

SPF vs DKIM vs DMARC Comparison

AspectSPFDKIMDMARC
ValidatesSending server IPSignature + contentPolicy + Alignment
Protects againstIP SpoofingMessage tamperingDomain spoofing (From:)
DNS locationTXT at @TXT at selector._domainkeyTXT at _dmarc
Email forwardingMay failUsually passesDepends on SPF/DKIM
ReportingNoneNoneYes (Aggregate + Forensic)

How to Configure SPF Record

An SPF record is a TXT record at your root domain (@) that always starts with v=spf1.

Basic Syntax

v=spf1 [mechanism...] [all]

Common SPF Mechanisms

MechanismMeaningExample
ip4:Allow IPv4 / subnetip4:203.0.113.10
ip6:Allow IPv6ip6:2001:db8::/32
include:Pull SPF from another domaininclude:_spf.google.com
aAllow the domain's A record IPa
mxAllow MX serversmx
~allSoftfail — others not permitted (recommended)~all
-allHardfail — reject all that don't match-all

Common SPF Record Examples

# Using own mail server and Google Workspace
v=spf1 mx include:_spf.google.com ~all

# Direct IP + Gmail
v=spf1 ip4:203.0.113.10 include:_spf.google.com -all

# Using AsiaGB Email
v=spf1 include:spf.asiagb.com ~all
💡 Important: A domain can only have one SPF record. Having more than one TXT record starting with v=spf1 causes an immediate SPF fail. Combine all entries into a single record.

Adding SPF in DirectAdmin

  1. Login to DirectAdmin → Email Manager → MX Records
  2. Or go to DNS Management → select your domain
  3. Add TXT Record: Name = @ or leave blank, Value = your SPF string
  4. Save and wait 0-48 hours for DNS propagation

How to Configure DKIM Record

DKIM requires a Key Pair generated from your mail server. You need to:

  1. Generate a Private Key + Public Key on your mail server
  2. Configure the mail server to sign outgoing mail with the Private Key
  3. Publish the Public Key via a DNS TXT Record

DKIM DNS Record Format

# Record name:
SELECTOR._domainkey.yourdomain.com

# Example with selector "mail2026":
mail2026._domainkey.yourdomain.com

# Value:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...

Generating DKIM Keys with OpenSSL

# Generate Private Key (2048-bit RSA)
openssl genrsa -out dkim_private.pem 2048

# Extract Public Key for DNS
openssl rsa -in dkim_private.pem -pubout -out dkim_public.pem
openssl rsa -in dkim_private.pem -pubout | grep -v "PUBLIC KEY" | tr -d '\n'
📌 DKIM in DirectAdmin: DirectAdmin supports DKIM through Email Manager → Domain Email Settings → Enable DKIM. The system generates the key pair and configures DNS automatically.

How to Configure DMARC Record

DMARC is a TXT record at the _dmarc subdomain of your root domain.

DMARC Record Format

# Record name:
_dmarc.yourdomain.com

# Start with monitor mode:
v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1

# Intermediate (quarantine):
v=DMARC1; p=quarantine; pct=50; rua=mailto:[email protected]

# Full enforcement (reject):
v=DMARC1; p=reject; rua=mailto:[email protected]; adkim=s; aspf=s

DMARC Tags Explained

TagMeaningValues
p=Main policynone / quarantine / reject
sp=Subdomain policynone / quarantine / reject
pct=% of emails subject to policy0-100 (default: 100)
rua=Aggregate report addressmailto:email@domain
ruf=Forensic report addressmailto:email@domain
adkim=DKIM alignment moder (relaxed) / s (strict)
aspf=SPF alignment moder (relaxed) / s (strict)

Safe DMARC Rollout Strategy

  1. Week 1-2: p=none — receive Aggregate Reports, identify all email sources
  2. Week 3-4: p=quarantine; pct=10 — start enforcing for 10% of messages
  3. Month 2: p=quarantine; pct=100
  4. Month 3+: p=reject — full enforcement

Testing and Verifying Your Setup

After configuration, wait 24-48 hours for DNS propagation before running tests.

Recommended Testing Tools

ToolTestsURL
MXToolBoxSPF, DKIM, DMARCmxtoolbox.com/SuperTool
mail-tester.comOverall score + spam scoremail-tester.com
DMARC AnalyzerAggregate Reportsdmarcanalyzer.com
Google Admin ToolboxGoogle's DNS checkertoolbox.googleapps.com/apps/checkmx
nslookup / digLocal DNS verificationterminal

Verify via Command Line

# Check SPF
nslookup -type=TXT yourdomain.com

# Check DKIM (selector: mail2026)
nslookup -type=TXT mail2026._domainkey.yourdomain.com

# Check DMARC
nslookup -type=TXT _dmarc.yourdomain.com

# Using dig
dig TXT yourdomain.com +short
dig TXT mail2026._domainkey.yourdomain.com +short
dig TXT _dmarc.yourdomain.com +short

Signs Your Configuration is Working

💡 Check Headers in Gmail: Open an email sent from your domain → 3-dot menu → Show original → Look for Authentication-Results — it should show spf=pass, dkim=pass, dmarc=pass

Summary: Go-Live Checklist

  • ✅ SPF TXT record set at @ with only one record
  • ✅ DKIM enabled on mail server + Public Key added to DNS
  • ✅ DMARC record added at _dmarc.yourdomain.com starting with p=none
  • ✅ Waited 24-48 hours for DNS propagation
  • ✅ Tested with mail-tester.com and MXToolBox
  • ✅ Read DMARC Aggregate Reports after 1 week
  • ✅ Gradually increased policy from none → quarantine → reject

Need an Email Hosting service that supports SPF/DKIM/DMARC with premium Spam Filtering? AsiaGB Email Filtering helps you configure everything correctly from day one.

Frequently Asked Questions

Do I need to set up all three: SPF, DKIM, and DMARC?
Yes, it is strongly recommended to set up all three. Each protects a different aspect: SPF validates the sending IP, DKIM verifies the message signature and integrity, and DMARC enforces the policy. Without all three, your protection is incomplete.
Why are my emails still going to spam after setting up SPF/DKIM/DMARC?
Common reasons include: DMARC policy is p=none (monitor only, no enforcement), email content contains spam keywords, sending IP is blacklisted, or domain reputation is new. Use mail-tester.com or MXToolBox for detailed diagnostics.
What DKIM key length should I use?
Use at least RSA 2048-bit, or ED25519 which is shorter but cryptographically stronger. Avoid 512 or 1024-bit keys — Google and Yahoo have rejected them since 2024.
What is the difference between DMARC rua and ruf?
rua (Aggregate Report) is a daily XML summary of all emails claiming to come from your domain. ruf (Forensic Report) is sent immediately for each individual failure event. Start with rua to monitor your email landscape before enforcing any policy.
How many include mechanisms can I have in SPF?
SPF is limited to 10 DNS lookups per record. Too many include statements can exceed this limit, causing SPF to fail entirely. Remove unused includes or use an SPF Flattening service if you need more.