ExplainerSoftware & systems

SPF, DKIM and DMARC explained: the email settings that help your invoices reach the inbox

What SPF, DKIM and DMARC do, what Gmail, Yahoo and Outlook require, what Australia's cyber agency recommends, and how to set them up without breaking email.

An envelope passing through a security checkpoint arch, on an emerald background. Three bold rubber-stamp marks on the envelope reading "SPF", "DKIM" and "DMARC", each with a green tick.
Illustration: Digital Advisors

Three records in your domain’s settings decide whether your quotes, invoices and newsletters land in the inbox, the spam folder or nowhere. They also make it harder for scammers to send email that looks like it came from your business. If nobody in your business can say whether you have all three, it’s worth finding out.

The big consumer mailbox providers now enforce them. Google, Yahoo and Microsoft can reject or junk email that fails their checks, and Australia’s cyber security agency tells organisations to go further.

The three records in plain English

All three live in your domain’s DNS, the settings held by whoever hosts your domain name.

  • SPF (Sender Policy Framework) is a list of the mail servers allowed to send email for your domain. In Google’s words, it “prevents spammers from sending unauthorized messages that appear to be from your domain.”
  • DKIM (DomainKeys Identified Mail) adds a digital signature to each message. Receiving servers use it “to verify that the domain owner actually sent the message”, and Microsoft says it also shows the message “remains unaltered in transit”.
  • DMARC ties the two together. It “tells receiving servers what to do with your messages that don’t pass SPF or DKIM”, such as deliver them anyway, send them to spam or reject them, and where to send reports about your mail.

Microsoft’s view is blunt: “Anything less than all of the email authentication methods results in substandard protection.”

What the mailbox providers require

These are the providers’ own rules. They’re not laws, but they’re enforced by whether your mail gets delivered.

Provider Who it applies to Authentication required DMARC Enforced since
Gmail (personal accounts) All senders SPF or DKIM Not required February 2024; stricter from November 2025
Gmail (personal accounts) Bulk senders: close to 5,000 or more messages a day SPF and DKIM At least p=none, aligned February 2024; stricter from November 2025
Yahoo and AOL All senders SPF or DKIM Not required February 2024
Yahoo and AOL Bulk senders (no number given) SPF and DKIM At least p=none, must pass February 2024
Outlook (Microsoft) Domains sending more than 5,000 emails a day SPF and DKIM must pass At least p=none, aligned 5 May 2025

A few details matter for smaller senders:

  • Gmail’s rules cover mail to personal Gmail addresses, those ending in @gmail.com or @googlemail.com. They don’t apply to mail sent to businesses that use Google Workspace. Google says a sender that reaches the bulk threshold “at least once” is “permanently considered” a bulk sender, and mail from the same primary domain counts together.
  • Gmail tightened enforcement in November 2025. Google says mail that doesn’t meet the requirements “will experience disruptions, including temporary and permanent rejections”. Google also says it’s “likely” that alignment with both SPF and DKIM will eventually be required.
  • Outlook rejects rather than junks. Microsoft first said failing mail would go to Junk, then updated its announcement on 29 April 2025 to say failing messages would be rejected from 5 May, with the error “550; 5.7.515 Access denied”. Parts of the announcement still describe the earlier Junk plan, but the dated update is the later statement. Adding yourself to a customer’s safe senders list doesn’t help: Microsoft says the “Safe Sender list won’t be honored.”
  • Marketing email needs easy unsubscribes. Gmail requires one-click unsubscribe for bulk marketing mail and recommends acting on requests within 48 hours. Yahoo says to honour them within 2 days. Transactional email, such as password resets and reservation confirmations in Google’s examples, is excluded from Gmail’s one-click rule.

On our reading, most small businesses aren’t bulk senders to any one provider, so only the “all senders” row applies to them directly. But a business whose newsletter reaches close to 5,000 Gmail addresses in a day can cross Gmail’s threshold once and stay classed as bulk. And even below the thresholds, Gmail and Yahoo require every sender to use SPF or DKIM.

What Australia’s cyber agency recommends

The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) goes further than the providers. Its guidance How to combat fake emails, written for businesses of all sizes and last updated in 2021, says “DMARC is critical – implement it now irrespective of your existing controls”, “even if only in a monitoring mode (‘p=none’) configuration”. The end goal is a DMARC record that “either quarantines or rejects 100 percent of email that fails SPF and DKIM checks”. For domains you own but never send email from, the ACSC recommends records that say so, so scammers can’t use them either.

Its advice on preventing business email compromise tells small businesses to “have a discussion with your service provider” about adding all three records, and to contact your DNS host too if that’s a separate company.

This is guidance, not law. On our reading, the providers’ rules are the hard requirement for getting mail delivered, and the ACSC’s advice is the standard for making it harder for scammers to send email that appears to come from your domain. Our guide to checking an invoice before you pay it covers the other side: checking what arrives.

Where small businesses trip up

  • Services that send as you. Your newsletter platform, website contact form, booking system and accounting software may all send email from your domain. Google says your SPF record “should include all email senders for your domain”, or their messages “are more likely to be marked as spam”. The ACSC suggests authorising marketing email providers with DKIM rather than SPF, using “a separate DKIM selector and key pair for each ESP” (email service provider). Microsoft suggests sending bulk marketing from a subdomain.
  • One SPF record, ten lookups. Microsoft says “only one SPF record is allowed per domain”, and if checking it takes more than 10 DNS lookups, “the message fails SPF”. Adding every service’s include line to one record can break it.
  • Microsoft 365 custom domains. Microsoft 365’s setup process has you add an SPF record, but Microsoft says “no DKIM signing occurs for outbound mail from custom domains” until you configure it, and DMARC isn’t created for you.
  • Google Workspace. An admin generates a DKIM key in the Admin console, publishes it in DNS and clicks Start authentication. Google says you must wait 24 to 72 hours after turning on Gmail before you can get the key. SPF and DMARC are added at your DNS host.

How to roll it out without breaking email

Google, Microsoft and the ACSC agree on the order. Start DMARC in monitoring mode, read the reports, then tighten it.

  1. List everything that sends email as your domain. Staff mailboxes, newsletters, forms, invoicing, bookings and your website.
  2. Fix SPF. One record that covers every sender, within the 10-lookup limit.
  3. Turn on DKIM for your mailbox provider and each sending service that supports it.
  4. Publish DMARC at p=none with a reporting address (the rua tag, which Google says to “always include”). Google says SPF and DKIM should be authenticating for at least 48 hours before you turn DMARC on.
  5. Read the reports. They show which services are sending as you and whether they pass. Google suggests at least a week at none.
  6. Tighten gradually. Microsoft advises “none → quarantine → reject”. Google suggests applying quarantine to a small percentage first, for example 10% for a small organisation.

Checklist

  • Ask your IT provider or domain host whether you have SPF, DKIM and DMARC for every domain you send from.
  • List every service that emails customers as you, and check it’s covered.
  • Check Microsoft 365 DKIM is set up for your own domain, not just the onmicrosoft.com one.
  • Check Google Workspace DKIM shows as authenticating in the Admin console.
  • Publish DMARC at p=none with reporting, then review the reports.
  • Plan the move to quarantine, then reject, as the ACSC recommends.
  • Protect unused domains with records that say they don’t send email.
  • If you send newsletters, check your platform handles one-click unsubscribe.