Skip to content
HostOn
Email

Setting up SPF, DKIM and DMARC: how to keep your emails out of spam

Are your emails landing in spam? SPF, DKIM and DMARC prove that messages really come from you. A step-by-step guide with examples for your own domain.

HostOn team6 min read
Illustration of email communication

Large email providers such as Gmail, Outlook and Yahoo now check for every message whether the sender is genuine. If the right DNS records are missing, even entirely legitimate emails end up in the spam folder – or are not delivered at all. Three records make the difference: SPF, DKIM and DMARC.

SPF: who may send for your domain?

The SPF record is a TXT record that lists all servers allowed to send emails on behalf of your domain. A simple example:

v=spf1 mx include:_spf.example-provider.ch -all
  • mx allows your domain’s mail servers.
  • include adds further senders, for example a newsletter service.
  • -all tells receiving servers to reject mail from any other server (~all only marks it as suspicious).

Tip: There may only be one SPF record per domain. Additional services are added with include in the same record.

DKIM: the digital signature

With DKIM, your mail server signs every outgoing message with a private key. You publish the matching public key as a TXT record, for example under dkim._domainkey.your-company.ch. Recipients use it to verify that the message was not altered in transit.

DMARC: what happens when checks fail?

DMARC builds on SPF and DKIM, checks alignment with the From address and defines how recipients should handle messages that fail the check. The record is located under _dmarc.your-company.ch:

v=DMARC1; p=none; rua=mailto:dmarc@your-company.ch
PolicyEffectWhen to use
p=nonemonitor only, receive reportsat the start
p=quarantinesuspicious emails go to spamafter a few weeks without errors
p=rejectsuspicious emails are rejectedwhen all senders are set up correctly

Step by step

  1. List all services that send emails on your behalf (mailbox, website, newsletter, invoicing software).
  2. Create an SPF record with all senders.
  3. Enable DKIM on the mail server and publish the key in DNS.
  4. Start DMARC with p=none and evaluate the reports.
  5. After a few weeks, raise it to quarantine and later to reject.

With HostOn’s email packages, SPF, DKIM and DMARC are already prepared – you only need to copy the records shown, or we set them up for you.

View Email hosting

EmailSPFDKIMDMARCSpam

Frequently asked questions on this topic

Yes. Since 2024, Gmail and Yahoo have required all three records from bulk senders, and they also noticeably improve delivery for small senders. The effort is small and only needed once.

-all (hard fail) rejects emails from servers that are not listed; ~all (soft fail) only marks them as suspicious. ~all is more cautious to start with; in the long term, -all is more secure.

Send an email to a Gmail account and open “Show original” there. You will see whether SPF, DKIM and DMARC passed.

Yes, if a legitimate sender is missing and -all is set. That is why you should first record all services and monitor with DMARC p=none before becoming stricter.

Share article

We are here for you

Whether before you order or in the middle of a project: you reach real specialists who understand what you need.

Workstations with headsets and laptops in a bright office