How to set up SPF, DKIM and DMARC

Three DNS records.
Or a 550 instead.

To set up SPF, DKIM and DMARC, you publish three records in the DNS of the domain you send from: one SPF record listing every service allowed to send for you, a DKIM key your email provider generates, and a DMARC record at _dmarc that starts at p=none. Gmail and Yahoo have required all three from bulk senders since February 2024, and Outlook since May 2025. Below: what each one does, a builder for the two you write yourself, and how it works with Builderify Broadcast.

Gmail · Yahoo · Outlook Rejecting unauthenticated bulk mail Checked 3 Oct 2026

By the Builderify team

01 No records: blocked 02 SPF, DKIM, DMARC published 03 Authenticated, accepted

Illustration. Accepted is not the same as the inbox: what you send, who to, and how many people mark it as spam still decide the folder.

01 / What they do

What SPF, DKIM and DMARC
each check, in plain English.

Each answers one question a receiving mail server asks about your message. They are all plain DNS records, added wherever your domain’s DNS is managed, and none of them touches your website.

01

SPF: is this server allowed to send for the domain?

A list of the services and addresses that may send mail for your domain. The receiver checks it against the domain in the hidden envelope sender (the Return-Path), not the From line people see.

TXT on the domain itself
v=spf1 include:_spf.google.com ~all
02

DKIM: was this message really signed by the domain?

Your provider signs every message with a private key; the public half sits in your DNS under a selector name. If the message is changed in transit, the signature stops matching.

TXT or CNAME at selector._domainkey
google._domainkey
03

DMARC: does a pass line up with the From address?

The rule that ties the two to the address people actually see, tells receivers what to do when neither lines up, and asks them to send you reports.

TXT at _dmarc
v=DMARC1; p=none

Alignment: the part most people miss

DMARC passes when SPF or DKIM passes for the same domain as your From address. By default that means the same organisational domain, so bounce.yourbrand.com lines up with yourbrand.com. Gmail, Yahoo and Outlook all require this for bulk mail.

It is also why many newsletter platforms never ask for an SPF include. They send with their own envelope domain, so SPF passes for them, not you, and DMARC leans on DKIM instead. Mailchimp’s setup, for example, asks for two DKIM CNAME records and a DMARC record, and no SPF.

02 / The rules

Gmail, Yahoo and Outlook
bulk sender requirements.

All three want the same thing from bulk senders: SPF and DKIM, a DMARC record of at least p=none, and a From domain that lines up with one of them. They differ in who counts as bulk and what happens when you miss.

Gmail, Yahoo and Outlook requirements for bulk email senders compared
Mailbox Who counts as bulk Since What bulk senders need If you miss it
Gmail Close to 5,000 or more messages a day to personal Gmail accounts, counted across your whole primary domain. Once bulk, always bulk. 1 February 2024; enforcement stepped up from November 2025 SPF and DKIM, DMARC (p=none is enough), From aligned with SPF or DKIM, one-click unsubscribe, spam rate under 0.3% Temporary and permanent rejections, such as 550 5.7.26 “This email has been blocked because the sender is unauthenticated.”
Yahoo “A significant volume of mail.” Yahoo deliberately does not publish a number. February 2024, rolled out gradually SPF and DKIM, DMARC of at least p=none that passes, From aligned, one-click unsubscribe honoured within 2 days, spam rate under 0.3% Filtering or blocking; Yahoo publishes no fixed code
Outlook Over 5,000 messages a day to outlook.com, hotmail.com and live.com addresses 5 May 2025 SPF pass, DKIM pass, DMARC of at least p=none aligned with SPF or DKIM (preferably both) Junk folder at first, then rejection: 550 5.7.515 “sending domain does not meet the required authentication level.”
Under 5,000 a day?

Set them up anyway. Gmail and Yahoo require every sender, whatever the volume, to pass SPF or DKIM and keep spam complaints under 0.3%. The bulk rules then apply the day a launch or a big list tips you over, and Google says that status never expires.

Who it applies to

These are rules for mail sent to personal Gmail, Yahoo and Outlook.com addresses. Google says its guidelines don’t apply to mail sent to Google Workspace accounts, but your list is almost certainly full of personal ones.

03 / SPF

An SPF record
for multiple senders.

Your SPF record is one TXT record on the domain, starting v=spf1, with an include: for each service that sends as you and an ending that says what to do with everyone else. Three rules decide whether it works.

  1. 1

    One record per domain.

    Two TXT records starting v=spf1 on the same name is a permanent error, and SPF fails for everything. Adding a new sender means editing the record you have, not adding a second one.

  2. 2

    Ten DNS lookups, at most.

    Every include, a, mx and exists costs a lookup, and so does every include nested inside them. Past ten, SPF fails. ip4 and ip6 cost nothing.

  3. 3

    ~all or -all at the end.

    Soft fail (~all) marks unlisted senders as suspicious; hard fail (-all) says reject them. Google suggests ~all, Microsoft -all. Either works with DMARC; use -all once you are sure the list is complete.

SPF record builder Runs in your browser
Services that send mail as this domain

Use the include your provider documents. Pasting existing records merges them into one.

Mail from anywhere else
Type TXT Host @ (yourbrand.com)
v=spf1 include:_spf.google.com ~all
1 of 10 DNS lookups Within the limit

Publish it as the only TXT record starting v=spf1 on yourbrand.com, replacing any you have now.

04 / DKIM

How to set up DKIM
for each service that sends.

You don’t write a DKIM record; each sending service generates its own key and tells you where to publish it. Unlike SPF, every service gets its own record under its own selector name, so there is nothing to merge. Turn signing on after the record resolves.

TXT at google._domainkey

Google Workspace

Admin console › Apps › Google Workspace › Gmail › Authenticate email. Generate a 2048-bit key if your DNS host allows it, publish it, then click Start authentication. Google says it can take up to 48 hours to start working.

Two CNAMEs: selector1 and selector2

Microsoft 365

Defender portal › Email & collaboration › Policies & rules › Threat policies › Email authentication settings › DKIM. Publish both CNAMEs it shows, then switch on Sign messages for this domain with DKIM signatures.

Usually CNAMEs

A newsletter platform

Look for “domain authentication” or “sender authentication” in its settings. Mailchimp, for example, gives you two CNAME records and a DMARC record to add.

What a receiver reads

Every signed message carries a DKIM-Signature header. Two parts matter to you: d= is the domain that signed, and must match your From domain for DMARC; s= is the selector, which tells the receiver where in your DNS to find the key.

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
    d=yourbrand.com; s=google;
    h=from:to:subject:date:message-id; bh=…; b=…
           ↑ signer               ↑ key lives at google._domainkey.yourbrand.com
05 / DMARC

A DMARC record example,
and what p=none means.

A good first DMARC record is v=DMARC1; p=none; rua=mailto:dmarc@yourbrand.com, published as a TXT record at _dmarc.yourbrand.com. p=none means “monitor only”: receivers deliver as they normally would and send daily reports of who is sending as you and whether it passed.

That satisfies Gmail, Yahoo and Outlook. It does not yet protect your domain from being spoofed; that takes quarantine or reject, once the reports show every real sender passing.

Older guides use pct= to phase in a policy. The updated DMARC standard, RFC 9989 (May 2026), removed it in favour of t=y, a testing flag that applies one step softer than the policy you set. Existing records keep working.

DMARC record builder Runs in your browser
Policy for mail that fails

Receivers deliver as they normally would and send you reports. It meets the Gmail, Yahoo and Outlook minimum, but it does not stop anyone spoofing your domain yet.

Type TXT Host _dmarc (_dmarc.yourbrand.com)
v=DMARC1; p=none; rua=mailto:dmarc@yourbrand.com

From monitoring to protection

  1. Day one
    p=none, with rua

    Publish it with SPF and DKIM. Meets the bulk sender rules from the first send.

  2. Two to four weeks
    Read the reports

    Every service sending as you shows up. Fix any that fail: a missing include, DKIM never switched on.

  3. When it's clean
    p=quarantine

    Failing mail goes to spam. Add t=y first if you want a softer step.

  4. Last
    p=reject

    Spoofed mail is refused. Keep reading reports whenever you add a new sender.

The reports arrive as zipped XML. They are readable, just not pleasant; a free tier of any DMARC report service turns them into a list of senders.

How to check all three passed

Send yourself a real message

From the service you just set up, to a personal Gmail address. Test sends from a preview button sometimes take a different path.

Open the original

In Gmail, open the message, choose Show original from the three-dot menu, and read the SPF, DKIM and DMARC lines at the top. You want PASS on all three, and the DKIM domain should be yours.

Fix the one that fails

SPF fail: the service is missing from your record, or you have two records. DKIM fail: the record has not propagated or signing is still off. DMARC fail with both passing: an alignment problem, usually a platform signing with its own domain.

06 / With Builderify

Setting up SPF, DKIM and DMARC
for Builderify Broadcast.

Broadcast sends newsletters and campaigns from your own domain, and Sequences sends automated follow-ups from the same one. The Domains page lists the exact records for your domain and checks them for you.

The DNS records Builderify asks for when you connect a sending domain
Record Type Host / name Value Why
Ownership TXT _builderify.news.yourbrand.com builderify-verify=… A token unique to your account, so nobody else can claim the domain.
Mail routing MX news.yourbrand.com mta-pool.builderify.net (priority 10) Brings replies, bounces and unsubscribes back into Inbox.
SPF TXT news.yourbrand.com v=spf1 include:spf.builderify.net -all Lets Builderify's servers send for the domain. Already have SPF here? Add the include to it instead.
DKIM CNAME bldrfy1._domainkey.news.yourbrand.com bldrfy1._domainkey.builderify.net Points at the key that signs every message you send.
DMARCRecommended TXT _dmarc.news.yourbrand.com v=DMARC1; p=none; Recommended rather than required; any valid DMARC record you already publish counts.

Example values for news.yourbrand.com. Your own ownership token and exact hosts are on the Domains page.

Use a subdomain if your mailboxes live elsewhere

Builderify’s setup includes an MX record, so that replies, bounces and unsubscribes come back to Inbox. On a domain whose mailboxes already run on Google Workspace or Microsoft 365, changing the MX would move that mail too. Send from a subdomain such as news.yourbrand.com instead: it gets its own MX, SPF and DKIM, your main domain’s mail is untouched, and its sending reputation stays separate, which Microsoft recommends for bulk mail anyway. A DMARC record on your main domain also covers its subdomains unless they publish their own.

  1. 01

    Connect a sender

    Pick the From name and address, on a domain you own. Free mailbox addresses such as Gmail or Outlook can’t be authenticated, so they can’t be used. Add a few honest sentences about your business and where your list came from.

  2. 02

    Get reviewed

    A person looks at every new sender, usually within one business day, to protect everyone’s deliverability. Publish the records in the meantime.

  3. 03

    Publish and check

    Add the records at your DNS host and press Check DNS now. The page also re-checks whenever you open it and once an hour. Sending unlocks when review and records are both done.

Sending with BuilderifyCredits
One email, one recipient0.5
Free every month250
Emails that covers500
Starter pack, $92,000 emails
  • SPF and DKIM line up with your From domain: bounces return to your own domain and messages are signed with it
  • One-click unsubscribe on every message; unsubscribed and bounced addresses are skipped
  • Per-organization hourly limits protect your sender reputation
  • No subscription; packs are one-time and never expire
Start free

The free credits are shared with any other module you use. Full rate card on the pricing page.

Authentication gets your mail judged on its merits; it does not guarantee the inbox. A list of people who asked to hear from you, and mail they want to open, still does most of the work. Broadcast is one of 19 modules on the same account; see them all.

Questions

SPF, DKIM and DMARC, before you ask.

Add three records at your DNS host: one SPF TXT record on the domain listing every service that sends for you, the DKIM record your email provider generates (TXT or CNAME at selector._domainkey), and a DMARC TXT record at _dmarc starting with p=none. Then send yourself a message and check that SPF, DKIM and DMARC all show PASS.

No. Two TXT records starting v=spf1 on the same name cause a permanent error, and SPF fails for every message. Merge every sender into one record with one include per service, and keep it under 10 DNS lookups.

p=none is monitor-only: receivers deliver mail as usual and send you reports about who is sending as your domain. It meets the Gmail, Yahoo and Outlook minimum for bulk senders, but it does not stop spoofing until you move to quarantine or reject.

Gmail and Yahoo require every sender to pass SPF or DKIM; DMARC becomes mandatory as a bulk sender. Google counts close to 5,000 messages a day to personal Gmail accounts across your primary domain, and that status never expires, so publishing p=none early costs nothing.

The Domains page in Builderify lists every record to add: an ownership TXT record, an MX record, an SPF include, a DKIM CNAME and a recommended DMARC record. Builderify checks them for you, and sending unlocks once they resolve and your sender has been reviewed.

Stop losing the visitors
you already paid for.

More leads from the traffic you already have, and follow-up that sends itself. Free to start. No card, no monthly fee.