The UK Small Business
Email Deliverability Experts

What Is SPF, DKIM and DMARC? A Plain-English Guide for Business Owners

Matt from email fix profile picture
Email Fix technician Matt explains what
these confusing acronyms actually mean
If you’ve ever been told “your emails are failing SPF” or “you need to set up DMARC,” and nodded along without really knowing what that meant — you’re not alone. 
 

These three settings sit quietly in the background of your domain, and most business owners never think about them until something goes wrong: emails landing in spam, customers saying they never received an invoice, or a supplier warning that your messages are being blocked entirely.

 This guide explains what each one actually does, why they exist, and why getting them wrong can cause more damage than not having them at all.

The problem they solve

Email was built in the early 1980s, long before spam and phishing were a concern. The system trusts, by default, that whoever says they’re sending an email from yourbusiness.co.uk really is you. There’s nothing built into email itself to check that.
 

That trust gap is exactly what scammers exploit — sending fake invoices, fraudulent payment requests, or phishing attempts that appear to come from a real company’s domain. Inbox providers like Gmail and Microsoft 365 know this, so over the last decade they’ve built increasingly strict systems to verify that a sender really is who they claim to be. SPF, DKIM and DMARC are the three records that let you prove it.

“Think of it like a passport, a wax seal, and a set of instructions for what to do with anyone who shows up without either.”

 

SPF — the guest list

SPF (Sender Policy Framework) is a public record you add to your domain that lists exactly which mail servers are allowed to send email on your behalf.

When another mail server receives a message claiming to be from you@yourbusiness.co.uk, it checks your SPF record to see if the server that actually sent it is on the approved list. If it isn’t, that’s a red flag — the message might be forged.

This is why SPF problems often show up after you add a new sending tool. If you start using an invoicing platform, a CRM, or an email marketing tool to send on your behalf, and you forget to add that tool to your SPF record, its emails will look unauthorised — even though you genuinely sent them.

Common SPF mistake: having more than one SPF record for a domain. Only one is allowed. If a web developer added one years ago and a new IT provider adds another without checking, mail servers won’t know which to trust — and deliverability quietly gets worse.

 

DKIM — the wax seal

DKIM (DomainKeys Identified Mail) works differently. Instead of listing approved servers, it attaches a digital signature to every email you send, generated using a private key only your mail server has. The receiving server checks that signature against a public key published on your domain.

If the signature matches, two things are confirmed: the email really did come from your domain, and it wasn’t altered in transit. If someone intercepts the message and changes even a single word, the signature breaks and the email fails DKIM.

“This is the closest thing email has to a wax seal on a letter — proof of origin and proof it wasn’t tampered with.”

Common DKIM mistake: switching email or marketing platforms and forgetting that DKIM keys are specific to each sending service. An old key for a platform you stopped using two years ago, still sitting in your DNS unused, isn’t harmful — but a missing key for a platform you’re actively using will cause every message from it to look suspicious.

 

DMARC — the instructions

SPF and DKIM verify identity. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do if a message fails those checks — and reports back to you when it happens.

A DMARC record has three possible policies:

  • nonetake no action, just monitor and report. Useful for seeing what’s happening before making changes.
  • quarantinesend anything that fails to the recipient’s spam folder.
  • rejectblock failing messages outright; they never reach the inbox, not even as spam.

This is the setting that carries real risk if it’s configured incorrectly. If your legitimate sending sources aren’t properly covered by SPF and DKIM first, and you set DMARC to reject, you can end up blocking your own genuine emails — including ones you’re not even aware are being sent on your behalf, like receipts from a booking system or automated confirmations from your website.

This is also why, from 2024 onward, Google and Yahoo began requiring at least a basic DMARC policy for any business sending meaningful volumes of email to Gmail or Yahoo addresses — without it, mail is increasingly likely to be filtered or rejected regardless of content.

Why "just turning it on" is riskier than it sounds

Each of these three settings depends on the others being correct first. SPF has to list every real sending source, or DMARC will flag them as failures. DKIM has to be correctly configured for every platform you use, for the same reason. And DMARC’s policy has to be tightened gradually — none, then quarantine, then reject — while watching the reports along the way, rather than jumping straight to full enforcement.

Get the sequence wrong, or miss one sending source, and the most common outcome isn’t “nothing happens” — it’s that some of your own legitimate email starts silently disappearing, with no error message telling you why.

Where to go from here

If you want to check where your domain currently stands, our guide on how to check if your domain’s email authentication is set up correctly walks through it step by step. If you’re already seeing symptoms — emails landing in spam, or customers saying messages never arrived — our guide on why your emails are going to spam covers the most common causes in more detail.

If it all sounds like more than you want to take on yourself, that’s exactly the gap we fill: we review your setup, tell you plainly what’s wrong, and fix SPF, DKIM and DMARC properly — in the right order, tested across major providers — so nothing breaks on the way to getting it right.

Need help fixing this?


We provide:
  • Free initial assessment
  • Clear explanation of the issue
  • Fixed-price solutions
  • UK-based support

If your emails are going to spam, we can identify the cause and fix it properly.

 

Get in touch
Online now (support available 24/7)
Pop in your details below and we'll bring you straight into the conversation.
Please fill in the required fields.
Emails going to spam
Website not sending emails
Not sure what's wrong
Set up business email