SPF, DKIM and DMARC in plain words

Updated Sep 2026 · 8 min read

Why your emails land in spam and the three records that fix it.

What a receiver does with one message

  1. 1
  2. 2
  3. 3

SPF: who may send

harborgoods.com.  TXT  "v=spf1 include:_spf.google.com include:sendgrid.net ~all"

DKIM: is the message untouched

google._domainkey.harborgoods.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqh…"

DMARC: what to do on failure

_dmarc.harborgoods.com.  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]; fo=1"

Reading a DMARC report

Rolling out DMARC without losing email

  1. 1
  2. 2
  3. 3
  4. 4

Check your records yourself

dig +short TXT harborgoods.com | grep spf1
dig +short TXT google._domainkey.harborgoods.com
dig +short TXT _dmarc.harborgoods.com
dig +short MX harborgoods.com

Forwarding, mailing lists and subdomains

Protect the domains that never send

parked-brand.com.         TXT  "v=spf1 -all"
_dmarc.parked-brand.com.  TXT  "v=DMARC1; p=reject"
parked-brand.com.         MX   0 .

When you change email provider

Common mistakes

Building an integration?REST API, webhooks and MCP server are documented separately.Open the docs