Setting up SPF, DKIM and DMARC: how to keep your emails out of spam
Are your emails landing in spam? SPF, DKIM and DMARC prove that messages really come from you. A step-by-step guide with examples for your own domain.

Large email providers such as Gmail, Outlook and Yahoo now check for every message whether the sender is genuine. If the right DNS records are missing, even entirely legitimate emails end up in the spam folder – or are not delivered at all. Three records make the difference: SPF, DKIM and DMARC.
SPF: who may send for your domain?
The SPF record is a TXT record that lists all servers allowed to send emails on behalf of your domain. A simple example:
v=spf1 mx include:_spf.example-provider.ch -all
- mx allows your domain’s mail servers.
- include adds further senders, for example a newsletter service.
- -all tells receiving servers to reject mail from any other server (~all only marks it as suspicious).
Tip: There may only be one SPF record per domain. Additional services are added with include in the same record.
DKIM: the digital signature
With DKIM, your mail server signs every outgoing message with a private key. You publish the matching public key as a TXT record, for example under dkim._domainkey.your-company.ch. Recipients use it to verify that the message was not altered in transit.
DMARC: what happens when checks fail?
DMARC builds on SPF and DKIM, checks alignment with the From address and defines how recipients should handle messages that fail the check. The record is located under _dmarc.your-company.ch:
v=DMARC1; p=none; rua=mailto:dmarc@your-company.ch
| Policy | Effect | When to use |
|---|---|---|
| p=none | monitor only, receive reports | at the start |
| p=quarantine | suspicious emails go to spam | after a few weeks without errors |
| p=reject | suspicious emails are rejected | when all senders are set up correctly |
Step by step
- List all services that send emails on your behalf (mailbox, website, newsletter, invoicing software).
- Create an SPF record with all senders.
- Enable DKIM on the mail server and publish the key in DNS.
- Start DMARC with p=none and evaluate the reports.
- After a few weeks, raise it to quarantine and later to reject.
With HostOn’s email packages, SPF, DKIM and DMARC are already prepared – you only need to copy the records shown, or we set them up for you.
Frequently asked questions on this topic
Yes. Since 2024, Gmail and Yahoo have required all three records from bulk senders, and they also noticeably improve delivery for small senders. The effort is small and only needed once.
-all (hard fail) rejects emails from servers that are not listed; ~all (soft fail) only marks them as suspicious. ~all is more cautious to start with; in the long term, -all is more secure.
Send an email to a Gmail account and open “Show original” there. You will see whether SPF, DKIM and DMARC passed.
Yes, if a legitimate sender is missing and -all is set. That is why you should first record all services and monitor with DMARC p=none before becoming stricter.



