Email & SMTP
Complete Email Authentication Setup (SPF+DKIM+DMARC)
Get SPF, DKIM and DMARC all set up correctly together, from a domain with little or no email authentication in place.
The Problem
Setting these up one at a time, without understanding how they interact, is how people end up with a DMARC policy that blocks their own newsletter or an SPF record that silently breaks. This does all three properly, in the right order.
About this problem
SPF, DKIM and DMARC are designed to work together, but each is independently easy to get slightly wrong, and doing them one at a time without understanding the interactions is exactly how a DMARC policy ends up blocking your own newsletter, or an SPF record silently exceeds its lookup limit the moment DKIM gets added.
This full setup is typically requested for a brand-new domain, after a rebrand or domain change, or when a business realises none of the three were ever properly configured together.
What's Included
- Auditing every service that currently sends mail from your domain
- Publishing a correct SPF record covering all of them
- Setting up DKIM signing and publishing the selector record
- Publishing a DMARC record with a sensible starting policy and reporting address
What's NOT Included
- Ongoing monitoring of DMARC reports after the initial setup
- Fixing deliverability issues unrelated to authentication, like IP reputation
- Email authentication for more than one domain unless agreed upfront
How It Works
- Audit every service currently sending mail from the domain — main inbox, CRM, invoicing, marketing tools, transactional senders.
- Build and publish a correct SPF record covering exactly those senders, within the 10-lookup limit.
- Generate and publish DKIM keys, then enable signing on every sending source that supports it.
- Publish a DMARC record starting at a monitoring-only policy with a working aggregate report address.
- Send live test mail through every sending source and confirm all three checks pass and align.
- Set a short review point to tighten the DMARC policy once reports confirm everything is accounted for.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Do I need SPF, DKIM and DMARC all at once?
- For proper protection, yes — SPF and DKIM alone don't stop spoofing, they just provide signals that DMARC then acts on. Setting up all three together also avoids the common mistake of misconfiguring one while fixing another.
- How long does a full email authentication setup take?
- The technical setup itself is usually done within a day once every sending source is identified; a short monitoring period afterwards is recommended before tightening the DMARC policy fully.
- Will this break my current email while it's being set up?
- No — SPF, DKIM and DMARC are DNS-based and additive; done correctly, legitimate mail keeps flowing throughout, and the final DMARC policy starts in monitor-only mode precisely to avoid any disruption.
- What if I add a new email tool after this setup?
- Any new sending service needs to be added to the SPF record and ideally configured for DKIM too, otherwise its mail may start failing alignment — this is a quick follow-up, not a full re-setup.
- Is this different from just fixing SPF, DKIM or DMARC individually?
- Yes — fixing them individually assumes the others are already correct; this is for building all three properly together from the ground up, in the right order, which avoids conflicts between them.
- Does this work for a brand-new domain with no email sent yet?
- Yes, this is actually the easiest case, since there's no existing misconfiguration to account for — everything is set up correctly from day one.