SurfaceWatch
← All articles
EMAIL SECURITY·October 2026·7 min read

SPF, DKIM and DMARC explained — and how to check your domain

Here's an uncomfortable fact: by default, anyone can send email that looks like it came from your domain. The "From" address is just text. SPF, DKIM and DMARC are three DNS records that fix that — they let receiving mail servers tell real email from spoofed email. If you've ever worried about someone phishing your customers "from" you, these are the controls that stop it.

They sound intimidating, but each one has a simple job.

SPF — who is allowed to send

Sender Policy Framework is a DNS record listing the mail servers allowed to send email for your domain. When a server receives mail claiming to be from you, it checks whether the sending server is on your list.

v=spf1 include:_spf.google.com include:sendgrid.net -all

The -all at the end means "reject anything not listed." That's the strict, correct ending once you're confident your list is complete.

DKIM — proof it wasn't tampered with

DomainKeys Identified Mail adds a cryptographic signature to each message. Your mail provider signs outgoing email with a private key; the matching public key lives in your DNS. The receiver verifies the signature, proving the message really came from you and wasn't altered in transit.

DKIM records live at a selector subdomain like selector1._domainkey.yourdomain.com, and your email provider (Google Workspace, Microsoft 365, SendGrid, etc.) gives you the exact value to publish.

DMARC — the policy that ties it together

DMARC tells receivers what to do when a message fails SPF and DKIM — ignore it, quarantine it (spam folder), or reject it — and asks them to send you reports so you can see who's sending as you.

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com

Start with p=none (monitor only, collect reports), then move to p=quarantine and finally p=reject once you're sure legitimate mail passes.

SPF vs DKIM vs DMARC, in one line each

You want all three. SPF and DKIM do the checking; DMARC enforces and gives you visibility.

How to check if your domain is protected

From a terminal:

# SPF
dig +short TXT yourdomain.com | grep spf1

# DMARC
dig +short TXT _dmarc.yourdomain.com

# DKIM (you need to know your selector)
dig +short TXT selector1._domainkey.yourdomain.com

If the SPF or DMARC lookups come back empty, you're exposed to spoofing. (DKIM is selector-based, so a generic check can't always find it without knowing the selector your provider uses.)

Prefer not to touch the command line? SurfaceWatch checks your domain's SPF and DMARC as part of its one-click website security grade, and flags it when either is missing — alongside your headers, HTTPS, cookies and exposed subdomains.

Email authentication protects your domain's reputation and your customers from phishing. It won't secure your website itself — but it's one of the cheapest, highest-impact things most small teams are missing.
Check your SPF & DMARC — add SurfaceWatch free