These three DNS records work together to prove your emails are genuinely from you, not an impersonator — and modern mail providers increasingly require all three.
SPF: Who's Allowed to Send
Sender Policy Framework lists which mail servers are authorized to send email on behalf of your domain. Receiving servers check this list and flag mail from unauthorized sources as suspicious.
DKIM: Proof the Message Wasn't Altered
DomainKeys Identified Mail adds a digital signature to outgoing email, letting receiving servers verify the message genuinely came from your domain and wasn't tampered with in transit.
DMARC: The Enforcement Policy
DMARC tells receiving servers what to do when a message fails SPF or DKIM checks — quarantine it, reject it, or just monitor and report. It also gives you visibility into who's sending email claiming to be from your domain.
Why This Matters
Without these records properly configured, legitimate email from your domain is more likely to land in spam folders, and it becomes easier for attackers to spoof your domain in phishing attempts against your own customers.
Setting Them Up
These are added as TXT records in your domain's DNS settings. CyberNet's hosted email comes with SPF and DKIM pre-configured; DMARC can be added as an additional TXT record to define your enforcement policy.
Español
Deutsch