Skip to content
websitecontrole.nl

Email check

Who may send mail that looks like it comes from your domain? SPF and DMARC are two records at your domain that decide this. Enter a domain and I read them and explain, line by line, what they say.

What is SPF?

SPF is a record at your domain that lists which servers may send mail on your behalf. A receiving mail server checks whether an incoming message came from one of them; if not, that is a sign the sender may be forged. SPF is to email what a Content-Security-Policy is to a page.

What is DMARC?

DMARC builds on SPF and DKIM. It tells receivers what to do with mail that fails the check: nothing (none), send to spam (quarantine), or reject it. And it sends you reports, so you see who sends for your domain. Without DMARC, anyone can send mail that looks like it comes from you.

What is DKIM?

DKIM puts a digital signature on every outgoing message. The receiver checks it against a key in your DNS, and so knows the mail was not altered in transit and really comes from your domain. You arrange DKIM with your mail provider; DMARC then checks that SPF or DKIM holds.

Why it matters

Email is not secure by default: without these records, someone can send mail with your domain as the sender, for phishing or fraud. SPF, DKIM and DMARC together make that much harder. Large providers like Google and Yahoo now require DMARC from anyone who sends in bulk. It sits apart from your website; these are records at your domain.

An example

This is what a simple, working pair looks like. The SPF record sits on your domain, the DMARC record on _dmarc.yourdomain.

v=spf1 include:_spf.google.com ~allv=DMARC1; p=quarantine; rua=mailto:dmarc@example.com

How to set it up

In four steps, from nothing to full protection. Roll it out calmly: start by watching, and tighten only once the picture is right.

  1. Publish SPF

    Add an SPF record to your domain that lists your senders and ends in -all or ~all. Usually that is an include of your mail provider.

  2. Turn on DKIM

    Enable DKIM with your mail provider. It gives you a record to add to your DNS.

  3. Start DMARC at none

    Publish a DMARC record with p=none and a rua address. You block nothing yet, but get reports on who sends for you.

  4. Raise to quarantine and reject

    Once the reports are clean and only your real senders appear, raise it to p=quarantine and then p=reject.

Frequently asked questions

Does this affect my website grade?

No. SPF and DMARC are about email, not about what a visitor risks on your page. So they do not count toward the grade; this page explains them on their own.

I barely send mail, do I need this?

Yes. Even a domain that sends little can be abused by someone else to send phishing. DMARC at reject shuts that down, precisely when you send little yourself.

Can I start at reject right away?

Better not. Start at none and read the reports, or you may block legitimate mail you forgot about. Raise it only once the picture is right.

Why can you not check DKIM?

The DKIM signature sits at a selector, a name that differs per sender and cannot be found from outside. We would have to guess, and we do not guess.

Read on