DnsGuard › Guides

Email authentication guides

Four DNS records decide whether your email is trusted, lands in spam, or can be spoofed, and two more protect mail on its way to you. Here is what each one does and how to get it right.

SPF

Which servers may send mail for your domain, the 10-lookup limit, and ~all vs -all.

DKIM

How signatures work, finding your selector, key length and rotation.

DMARC

Alignment, p=none vs quarantine vs reject, reports, and a safe rollout plan.

BIMI

Showing your logo in the inbox: DMARC requirements, SVG format and certificates.

MTA-STS & TLS-RPT

Encrypted delivery to your mail servers: the policy file, testing vs enforce, and TLS reports.

In what order should I set them up?

  1. SPF: list the services that send mail as your domain.
  2. DKIM: turn on signing with your own domain in each of those services.
  3. DMARC: start at p=none with reports, then move to quarantine and reject.
  4. BIMI: once DMARC is enforced, publish your logo.
  5. MTA-STS and TLS-RPT: optional, for the mail you receive. Turn on TLS reports, then an MTA-STS policy in testing mode, then enforce.

Check your domain now

Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.