DMARC · SPF · DKIM
DMARC, SPF & DKIM setup guides
Step-by-step DNS setup for email authentication. Start with SPF and DKIM, publish DMARC monitoring, then use reports to move toward enforcement.
DMARC setup guide
Publish a safe p=none monitoring record, collect aggregate reports, then move toward p=reject without guessing.
SPF setup guide
List authorised senders correctly, stay under the 10-lookup limit, and avoid SPF permerrors.
DKIM setup guide
Turn on signing for each sender, publish selectors, and confirm signatures on real mail.
How to read DMARC aggregate reports
Which rua fields matter — source, volume, disposition, and alignment — so you can act, not archive.
Fix SPF permerror without breaking mail
Diagnose lookup limits and includes so legitimate senders keep passing while you clean the record.
DMARC enforcement path: p=none to p=reject
A practical, low-drama path from discovery through quarantine to reject.
Lookalike domains vs spoofing
DMARC stops forgery of your exact domain. Lookalikes need different defences — know the difference.
MTA-STS and TLS-RPT
Transport security and reporting after SPF, DKIM, and DMARC are under control.
When BIMI makes sense
Logo display only after enforcement and brand requirements are in place.
RFC standards reference
What DMARC Shield monitors: DMARC, SPF, DKIM, BIMI, MTA-STS, TLS-RPT, ARC.
Prefer a live check first?
Run free domain tools, then compare plans when you are ready for ongoing monitoring.