Brisbane, QLD ·
The three records that matter
SPF lists the servers permitted to send on behalf of your domain. It must include every legitimate sender: your mail platform, your CRM, your accounting system, your marketing tool and your website's form handler.
DKIM cryptographically signs outgoing mail so a receiver can verify it was not altered and genuinely came from an authorised platform.
DMARC tells receivers what to do when SPF and DKIM fail, and where to send reports. Without DMARC, the other two records provide far weaker protection against someone spoofing your domain.
Move to enforcement in stages
Start at p=none with reporting enabled and read the aggregate reports for a few weeks. They will reveal senders you had forgotten about.
Once legitimate traffic is fully aligned, move to p=quarantine, then to p=reject. Jumping straight to reject is the fastest way to lose real invoices.
Protect the domains you do not send from
Parked domains, retired brand domains and typo-catching domains should all carry a restrictive SPF record and a DMARC policy of reject. An unused domain with no policy is an attractive impersonation vehicle.
Check yours before a customer tells you
Our free domain and email health check queries your live DNS and reports on SPF, DKIM discovery, DMARC policy, CAA and DNSSEC in a few seconds, with plain-English notes on what each result means.
In short
SPF, DKIM and a DMARC policy at reject are now the baseline for reliable business email delivery. Stage the rollout, read the reports, and cover your parked domains too.
