Send Us A Message

Bee More Media

divinext

Securing your email domain is critical for maintaining high deliverability and protecting your brand's reputation with patients, clients, and partners. This dkim spf and dmarc setup guide for small business domains walks you through securing your domain step-by-step.

Quick answer: To configure SPF, DKIM, and DMARC, inventory all email-sending platforms, create a single TXT record for SPF containing all authorized services, publish public DKIM keys provided by your sending services, and publish a DMARC TXT record at _dmarc.yourdomain.com starting with a monitoring policy (p=none) before advancing to enforcement.

Key Takeaways

  • SPF specifies which IP addresses and services can send mail from your domain.
  • DKIM attaches an encrypted digital signature to verify that email content has not been altered in transit.
  • DMARC instructs receiving mail servers how to handle messages that fail SPF or DKIM checks.
  • Never publish more than one SPF TXT record on a single root domain, and keep mechanisms under the 10-DNS-lookup limit.
  • Begin your DMARC deployment in monitoring mode (p=none) to review reports before enforcing quarantine or reject policies.

What Are SPF, DKIM, and DMARC and How Do They Work Together?

From below of long thin blue cables connected to row of small white connectors on system block in data center
Photo by Brett Sayles on Pexels

SPF, DKIM, and DMARC are three distinct email authentication protocols that work in unison to verify sender identity and prevent domain spoofing. Together, they establish a secure chain of trust between your sending server and the recipient's inbox provider.

Protocol RFC Standard Primary Function DNS Record Type
SPF (Sender Policy Framework) RFC 7208 Authorizes specific IP addresses and third-party platforms to send on your behalf. TXT at root domain (@)
DKIM (DomainKeys Identified Mail) RFC 6376 Validates that message headers and body were not modified in transit using public-key cryptography. TXT or CNAME at selector._domainkey
DMARC (Domain-based Message Authentication) RFC 7489 Sets enforcement policies (none, quarantine, reject) and generates reporting on authentication results. TXT at _dmarc

SPF checks whether the sending server's IP address is on your approved list. DKIM checks whether the cryptographic signature on the email matches the public key published in your DNS. DMARC aligns these checks against the visible "From" address and instructs receiving servers what to do if both checks fail.

Why Is Email Authentication Required for Small Business Domains?

Major mailbox providers like Google and Yahoo require proper email authentication for custom domains to reduce spam, phishing, and domain impersonation. Without valid SPF, DKIM, and DMARC records, messages sent from your business or practice are far more likely to land in spam folders or be blocked entirely.

For wellness clinics and local service providers, deliverability issues directly disrupt appointment reminders, intake forms, and automated marketing newsletters. Proper authentication protects your domain reputation, prevents cybercriminals from sending fraudulent messages using your business name, and ensures your legitimate communications reach the inbox.

Step 1: Conduct a Pre-Setup Email Sending Audit

Before adding or editing DNS records, compile a complete list of every service that sends email using your domain name. Missing a service during setup can cause legitimate business emails to fail authentication checks.

Check for sending services across your entire business stack:

  • Primary Mailboxes: Google Workspace, Microsoft 365, or webmail hosting.
  • Marketing & Newsletters: Mailchimp, Klaviyo, HubSpot, or ActiveCampaign.
  • Practice & Business Management: Scheduling platforms, electronic intake tools, and CRM systems.
  • Website & Transactional Mail: WordPress notification plugins, transactional SMTP relays, and invoicing software.

Step 2: How Do You Create and Publish a Single SPF Record?

An SPF record is created by publishing a single TXT record on your root domain that includes all authorized sending hosts using the include: mechanism. You must never publish more than one SPF TXT record for a domain, as multiple records cause an automatic SPF PermError.

  1. Log in to your DNS management console (such as Cloudflare, GoDaddy, or Namecheap).
  2. Locate existing TXT records on your root domain (@) and check for any existing entry starting with v=spf1.
  3. Combine all your sending providers into one string. For example, a business using Google Workspace and Mailchimp would construct:
    v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
  4. Ensure the record stays under the strict 10-DNS-lookup limit defined in RFC 7208. Each include: mechanism typically triggers one or more nested lookups.
  5. Save the TXT record at host @ with a standard TTL (e.g., 3600 seconds).

Step 3: How Do You Generate and Configure DKIM Keys?

DKIM is configured by generating a public/private key pair inside each sending service and publishing the public key in your DNS settings. The sending provider holds the private key to sign outgoing emails, while receiving servers query your DNS to verify the signature using the public key.

  1. Open the administrative dashboard of your email service (e.g., Google Workspace Admin Console or Microsoft 365 Defender).
  2. Navigate to the email authentication section and generate a new DKIM key (select a 2048-bit key standard whenever supported).
  3. Note the selector prefix provided (such as google or s1) and the public key string.
  4. In your DNS manager, create a new TXT or CNAME record. The host name follows the structure selector._domainkey.yourdomain.com.
  5. Paste the key string into the record's value field and save.
  6. Return to your email provider's console and click "Start Authentication" or "Verify" to activate DKIM signing.

Step 4: How Do You Implement DMARC with a Phased Rollout?

DMARC is implemented by creating a TXT record at the subdomain _dmarc.yourdomain.com, starting with an observation policy (p=none) before progressing to strict enforcement. Starting with an observation policy prevents accidental delivery failures while you monitor your aggregate reports.

  1. Phase 1 (Monitoring): Publish your initial DMARC record to collect aggregate data without affecting delivery:
    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; pct=100;
  2. Phase 2 (Quarantine): Once aggregate reports confirm all legitimate sources pass SPF/DKIM alignment, update the policy to route failing mail to spam folders:
    v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100;
  3. Phase 3 (Full Rejection): Once your sending pipeline is completely validated, update to full enforcement to block unauthorized spoofing attempts:
    v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; pct=100;

Note: Raw DMARC aggregate reports arrive as complex XML files. Rather than sending reports to a standard personal inbox, connect your rua tag to a dedicated DMARC analysis tool or reporting service to visualize delivery health.

Understanding DMARC Identifier Alignment for Third-Party Senders

Professional business meeting with a team analyzing data on a presentation screen.
Photo by Artem Podrez on Pexels

DMARC passes only when the domain in the visible "From:" header matches the domain authenticated by SPF (Return-Path) or DKIM (the d= signature tag). Passing SPF or DKIM on its own is not enough if the domains do not align.

When sending marketing emails through third-party platforms like Klaviyo, HubSpot, or Mailchimp, the platform may send from its own shared Return-Path domain by default. To achieve DMARC alignment, configure a custom sending domain or branded return path within that platform's account settings so that both SPF/DKIM signatures reflect your actual business domain.

How to Test and Verify Your DNS Records

You can verify active DNS authentication records using free diagnostic lookup tools immediately after saving changes. DNS propagation typically takes between 15 minutes and 24 hours.

  • Google Admin Toolbox CheckMX: Validates MX, SPF, and DKIM configuration for primary mailboxes.
  • MXToolbox SuperTool: Checks syntax, multiple-record conflicts, and lookup counts for SPF and DMARC.
  • Mail-tester.com: Generates an end-to-end score by analyzing an actual test email sent from your software.

Frequently Asked Questions

Can I have more than one SPF record on my domain?

No, you must never publish more than one SPF record on a single domain. Publishing multiple SPF TXT records causes receiving servers to return a permanent error (PermError), which can lead to your emails failing authentication.

What happens if I jump straight to a DMARC reject policy?

Setting your DMARC policy directly to p=reject without a monitoring phase risks blocking legitimate transactional emails, CRM notifications, or third-party newsletters that have not yet been aligned with your domain.

Why does an email fail DMARC even if SPF passed?

An email fails DMARC if the domain authenticated by SPF does not match the domain shown in the visible "From:" header. This commonly occurs when third-party software sends emails using their own server's Return-Path address instead of your custom domain.

What is the SPF 10-DNS-lookup limit?

The SPF specification (RFC 7208) limits the number of domain lookups during an SPF check to 10. If your record includes too many third-party services that trigger additional queries, it produces an SPF PermError and fails validation.