Skip to content
Email Deliverability and Automation Expert Email Deliverability and Automation Expert
  • Home
  • ReengagePro
  • Email Deliverability
  • Blog
  • Clients
  • About
  • Contact Us
Email Deliverability and Automation Expert
Email Deliverability and Automation Expert

Unraveling DMARC, DKIM, and SPF

Fabrício Yutaka Fujikawa, September 30, 2024September 30, 2024

Hi,

I needed to explain the DMARC, DKIM, and SPF protocols in simple terms to a non-technical person. As an experiment, I asked Claude for help, and he generated the following explanation:

“Imagine that SPF and DKIM are like two security guards at a building, checking if the person (the email) entering has authorization to do so.

SPF checks if the person came from a known address (server), and DKIM verifies if the signature on the badge is valid (the message content hasn’t been altered). So far, everything seems fine, but there’s a third level of security: DMARC.

DMARC is like a building manager who, in addition to verifying that the two guards authorized entry, wants to ensure that the company (domain) this person represents is indeed the one written on their uniform (the “From:” field in the email). The problem occurs when the person is authenticated, but the uniform they’re wearing (the “From:” field) doesn’t match the company represented by the person.

This misalignment happens when the domain that appears in the “From:” field (the uniform) is different from the domain authenticated by SPF or DKIM. In other words, even if SPF and DKIM are correct, DMARC will fail because the domains are not aligned, indicating potential forgery or a configuration issue.

In practical terms:

  • SPF confirms that the server the email came from is authorized to send emails on behalf of the domain.
  • DKIM confirms that the email content hasn’t been altered.
  • But DMARC fails because the domain that appears in the “From:” field of the email doesn’t correspond to the one authenticated by SPF or DKIM.

Imagine that, in addition to the security guards and the manager (SPF, DKIM, and DMARC), there are different buildings (mailbox providers, like Gmail, Outlook, etc.), and each of these buildings has its own rules on how to deal with people who don’t pass all security checks.

When an email fails DMARC authentication because the domain in the “From:” field isn’t aligned with the domains authenticated by SPF or DKIM, each mailbox provider (ESP) may react differently:

  • Some providers might put this email directly in the SPAM box, as they see this failure as a possible fraud or phishing attempt.
  • Other providers might simply reject the email and not deliver it to the inbox, meaning the recipient will never see the message.
  • Depending on the DMARC policy configured for the domain (for example, “none,” “quarantine,” or “reject”), the provider may take more severe measures. If the sender’s DMARC policy is set to “quarantine,” there’s a good chance the email will go straight to SPAM. If it’s “reject,” the provider might not even allow the email to reach the recipient.

In other words, the risk of not properly aligning SPF, DKIM, and DMARC is that your messages may end up being filtered as SPAM or not delivered at all, depending on the rules and settings of each provider. This is particularly dangerous because, even if the sender is legitimate, a DMARC failure can prevent the message from reaching the inbox, harming the domain’s deliverability and reputation.

With this, ensuring that all domains are aligned in SPF, DKIM, and DMARC not only improves security but also increases the chances of your messages reaching recipients correctly.”

What did you think of the explanation? Overall, I found it easy to understand.

To generate the post image, I asked Claude to create a description. The result was this:

“A minimalist and professional vector illustration using pastel tones. The image depicts a modern corporate building seen from the front, with a main entrance.

In the center of the image, there are three stylized figures representing:

A security guard (SPF) checking a badge. Another security guard (DKIM) examining a signature on a document. A manager (DMARC) standing between the two guards, observing attentively. In front of the building, there’s a line of people (representing emails) waiting to enter. Some people wear uniforms that match their badges, while others have different uniforms.

At the top of the building, there’s a discreet sign with the acronyms “DMARC, DKIM, SPF.

The background of the image is simple, with a sky in a soft pastel tone, creating a subtle contrast with the building.

The color palette should be predominantly in pastel tones, such as light blue, aqua green, beige, and light gray, to maintain a professional and sober appearance.

The image should be in 16:9 (landscape) format and optimized for a blog post.”

Then, in ChatGPT, I used the Custom GPT Image Generator Pro and asked it to generate the image. The first version was this:

Lastly, I asked it to focus only on the security guard and manager figures, as I wanted to emphasize DMARC’s “orchestrator” function. And then it generated the image at the top of the post.


Do you have any questions about email deliverability or want to share your experience? Leave a comment below!

Cheers,
Fabrício

Email Deliverability

Post navigation

Previous post
Next post

Related Posts

Case Studies

Mini Case Study: Sender Domain Reputation Recovery in Google Postmaster Tools

October 7, 2024October 7, 2024

Hi, Recently, a client approached me saying they had acquired a new website for their business group and needed to transfer the old email marketing infrastructure to their Martech (marketing technology platforms): We made the necessary configurations, including handling bounces and spam complaints, following FunnelKit’s instructions for SES and Sendgrid/Twilio….

Read More
Email Deliverability

Email Deliverability Journal – May 6th

May 6, 2024May 6, 2024

Hi, I recently received a retargeting email (also known as browse abandonment). I was researching email marketing tools to recommend to a client and visited this page on the Emailtooltester website. A few days later (maybe the next day), I received this email: This retargeting email is a prime example…

Read More

How to Warm Up a New Sender Domain

May 1, 2025April 30, 2025

Resend’s article, “How to Warm Up a New Domain,” offers a practical guide for establishing a solid reputation when you start sending emails from a new domain. Even with opt-in lists, or even double opt-in lists, it’s essential to follow a warming process to ensure high deliverability. Key Highlights Separation…

Read More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


  • Case Studies
  • Email Deliverability
  • Email Deliverability Case Studies
  • Google Workspace
  • Others
  • Outbound Email Authentication: Security & Deliverability
  • Referral Marketing

  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Cookie policy
©2026 Email Deliverability and Automation Expert | WordPress Theme by SuperbThemes
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT