All articles
DeliverabilityBy Efe Berke Çolaker 11 min read

SPF, DKIM & DMARC Explained in Plain English (2026 Guide)

What SPF, DKIM and DMARC actually do, why Gmail and Yahoo require them, and the exact records to publish, explained without jargon in one guide.

ON THIS PAGE
  1. 01Why it stopped being optional
  2. 02SPF: the guest list
  3. 03DKIM: the wax seal
  4. 04DMARC: the policy
  5. 05The safe rollout order
  6. 06Check your setup free
  7. 07FAQ
SPF, DKIM & DMARC Explained in Plain English (2026 Guide)
SPF, DKIM and DMARC explained: the three email authentication records required in 2026
SPF, DKIM and DMARC explained: the three email authentication records required in 2026

Email authentication sounds like plumbing until Gmail starts rejecting your mail. If you send cold email and your domain is not authenticated with SPF, DKIM and DMARC, your campaigns are rejected or spam-foldered before a human ever sees them. Here is what each record actually does, in plain English, with the exact steps to set them up.

3records
2024+required by Gmail & Yahoo
p=nonesafe starting policy
KEY TAKEAWAYS
SPF lists which servers may send for your domain.
DKIM cryptographically signs each message so it cannot be forged.
DMARC tells receivers what to do when a message fails, and sends you reports.
Roll out in order: SPF and DKIM first, then DMARC at p=none, then tighten.

Why authentication stopped being optional

Since February 2024, Google and Yahoo require SPF, DKIM and DMARC from anyone sending volume. Miss one and your mail is rejected or spam-foldered on arrival, no matter how good the copy is. This is the single most common reason a cold email domain suddenly stops landing in the inbox.

SPF: the guest list

SPF (Sender Policy Framework) is a DNS TXT record listing which mail servers are allowed to send email for your domain. When mail arrives claiming to be from you, the receiver checks the sending server against your list. Not on it? Suspicious.

It looks like v=spf1 include:_spf.google.com ~all. Two rules matter: you may have only one SPF record (two is an automatic fail), and you must stay under 10 DNS lookups. Generate a valid one with the free SPF record generator.

DKIM: the wax seal

DKIM (DomainKeys Identified Mail) cryptographically signs every message you send. The public key lives in your DNS under a selector (like google._domainkey); receivers use it to confirm the message was not altered and genuinely came from your domain. Your email provider (Google Workspace, AWS SES, Resend) generates the key and gives you the record to publish.

DMARC: the policy

DMARC ties SPF and DKIM together and answers one question: what should receivers do when a message fails? Three options:

  • p=none: do nothing, just send reports (start here).
  • p=quarantine: send failing mail to spam.
  • p=reject: refuse failing mail outright (full protection).

It is published at _dmarc.yourdomain.com. Build a valid record with the free DMARC record generator.

Getlead dashboard with warm-up and verification that protect authenticated domains
Getlead dashboard with warm-up and verification that protect authenticated domains

The rollout order that does not break delivery

Order matters. Publish SPF and DKIM first. Then add DMARC at p=none for 2 to 4 weeks while you read the aggregate reports and fix any sender that fails. Then move to p=quarantine, then p=reject. Jumping straight to reject with a misconfigured sender silently kills your own legitimate mail.

Check your setup in 10 seconds

Run your domain through the free deliverability test: it checks all three records plus MX and scores the result. Then keep the authenticated domain healthy with warm-up and verified lists via the email verifier. The full deliverability playbook is in our deliverability guide.

Authentication is step one. Getlead handles the rest.
Warm-up, SMTP verification and cold email sending built to land in the inbox, plus free tools to fix your DNS. From $19.90 a month.
See Getlead

FAQ: SPF, DKIM and DMARC

Do I really need all three?

Yes. Since 2024 Gmail and Yahoo require SPF, DKIM and DMARC from volume senders. Missing one means rejection or spam.

Which DMARC policy should I start with?

Start with p=none to collect reports without affecting delivery, then tighten to quarantine and reject over 2 to 4 weeks.

Can I have two SPF records?

No. Multiple SPF records are invalid and fail authentication. Merge all senders into one record with the SPF generator.

How do I check if my records are correct?

Use the free deliverability test, which validates SPF, DKIM, DMARC and MX and scores your domain.

Popular resources

Lead scrapers for 10+ sources15 best lead generation tools420M+ B2B lead databaseB2B email lists by industryRe-Engagement & Win-Back cold email templatesEcommerce & DTC cold email templatesConsulting & B2B Services cold email templates

More in Deliverability

DMARC Policy: Going From p=none to p=reject Without Losing Mail10 Best Pre-Warmed Email Account Providers Compared (2026)Spam Complaint Rate: The One Metric That Ends Cold Email ProgramsGmail, Yahoo and Microsoft Sender Requirements: The 2026 ChecklistWhy Cold Emails Land in Spam: A Diagnostic Order of OperationsDedicated Sending Domains: How to Set Them Up Without Wrecking Your Main One
Open the full deliverability guide

Customer reviews

2,400+ users. Real results.

Don't take our word for it

Replace your whole lead gen stack

Lead scraping, a 420M+ B2B database, email verification and cold email sending in one subscription. No credits, no seat pricing, cancel anytime.

Start from $19.90/mo
14-day money-back guarantee Instant access 12,400+ teams