SPF, DKIM and DMARC: Why Your Emails Aren’t Getting Through (and How to Fix It)

Since February 2024, Gmail and Yahoo require domains that send them email to be authenticated with SPF, DKIM and — for bulk senders — DMARC. Without this configuration, your messages risk landing in spam or being rejected outright, even when they’re perfectly legitimate. For an SMB, that’s very concrete: quotes that never arrive, invoices that go unread, lost form confirmations. The good news: the setup is done once, in your domain’s DNS settings, and fixes the problem for good.

Why these requirements exist

Phishing relies largely on identity spoofing: a fraudster sends an email that appears to come from your domain. Authentication protocols let mail servers verify that a message really comes from you. The major providers have stopped tolerating unauthenticated domains — and other email services apply increasingly similar filters. A properly configured domain therefore protects both your deliverability and your reputation.

SPF, DKIM, DMARC: the three protocols in plain language

  • SPF (Sender Policy Framework): the guest list. You publicly declare which servers are allowed to send email on behalf of your domain. Anything sent from elsewhere becomes suspicious.
  • DKIM (DomainKeys Identified Mail): the seal of authenticity. Each message is digitally signed, proving it really comes from your domain and hasn’t been altered in transit.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): the house policy. It tells receiving servers what to do with a message that fails the checks — deliver it anyway, quarantine it or reject it — and sends you reports on attempts to spoof your domain.

The signs of a poorly configured domain

  • Your customers say they don’t receive your emails, or find them in their junk folder.
  • Confirmations sent by your website (contact forms, orders) go missing.
  • Your newsletter shows plummeting delivery rates.
  • Fraudsters send emails impersonating your business, and nothing blocks them.

A common trap for SMBs: every tool that sends email in your name — your mailbox, your WordPress site, your newsletter platform, your invoicing software — must be covered by the configuration. We regularly see domains where the main mailbox is set up properly, but the website’s emails go out unauthenticated and disappear.

How to check and fix the situation

Checking takes a few minutes with free online tools (search for “SPF DKIM DMARC checker”): enter your domain and you’ll see which records exist. Fixing it happens in your domain’s DNS zone — at your registrar or your hosting provider. It’s a one-time operation, but a delicate one: a badly written SPF record can block your own emails, and a DMARC policy that’s too strict too soon can get legitimate messages rejected. You proceed in stages, watching the reports.

If you’d rather not touch your DNS yourself — and that’s understandable — we regularly configure SPF, DKIM and DMARC for our clients as part of our complementary services, often at the same time as setting up their web hosting. Write to us: a quick audit of your domain lets us tell you within a few hours whether your emails are at risk.

Renforcez la sécurité de vos emails : SPF, DMARC et DKIM