Complete SPF record setup guide, including syntax explanation and best practices
Configure DANE for SMTP with TLSA records to enforce secure delivery
Set up MTA-STS policy with Cloudflare for secure SMTP delivery
DKIM and DMARC work best when deployed jointly. DKIM provides cryptographic signatures that receivers can validate, and DMARC defines a policy that requires alignment between the visible From: domain and an authenticated identifier (DKIM d= or SPF). This guide outlines a pragmatic rollout plan.
dkim=pass in Authentication-Results.Start with a monitoring policy to discover all legitimate sources and see alignment status:
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-aggregate@example.com; adkim=s; aspf=s"
Strict alignment (s) reduces spoof risk; relax if needed during migration (r).
d=example.com (or an aligned organizational domain) matching the From: address.p=quarantine after validating sources and observing clean reports.p=reject for strong protection once confident.sp= for subdomain policy and fine-tune pct= during staged rollout.d= domains that don’t align.With DKIM signatures in place and DMARC gradually enforced, your domain gains strong protection against spoofing while improving deliverability signals to major receivers.