Browse the Learning Center
Learning paths
Ordered reading paths through DMARC, SPF and DKIM — from an unprotected domain to an enforced policy.
Get to p=reject
The full route from an unprotected domain to an enforced policy, in the order the work actually happens.
- What DMARC actually does
- Publish your first record
- Read your first report
- Fix SPF before you tighten
- Move to quarantine, then reject
The three records
SPF, DKIM and DMARC explained in the order they make sense — start here if the acronyms are new.
- SPF: who may send
- DKIM: proving it wasn't altered
- DMARC: what to do on failure
Add a sending platform
Authorise a new ESP without breaking the authentication you already have.
- Know what you're editing
- Add the platform's records
- Stay under the lookup limit
Fix a failing sender
Mail is bouncing or landing in spam. Work the causes in order of likelihood.
- Read the failure
- Check DKIM alignment
- Body-hash failures