How to set up SPF, DKIM, and DMARC for your sending domain
spy888
75 points
27 comments
October 01, 2026
Related Discussions
Found 5 related stories in 77.0ms across 8,245 title embeddings via pgvector HNSW
- DMARC has been public since 2012 but most company domains still don't enforce it adulion · 182 pts · July 28, 2026 · 49% similar
- PCI DSS DMARC Requirement: What Section 5.4.1 Requires meysamazad · 12 pts · July 24, 2026 · 48% similar
- Show HN: Make senders work to get into your inbox felixdoerp · 41 pts · July 15, 2026 · 40% similar
- SendLang: A DSL for Email Automation ksajadi · 13 pts · July 15, 2026 · 38% similar
- An update on leaving Gmail for Fastmail neogodless · 170 pts · August 17, 2026 · 38% similar
Discussion Highlights (8 comments)
comrade1234
You also need to set up reverse dns to avoid ending up in spam folders at the big ones.
adiabatichottub
I recently tried bouncing mail during the header phase when DMARC didn't align, but it rejected more legit emails than SPAM. Most of the junk we've been getting passes DMARC and has an unsubscribe link.
buredoranna
This looks like a pretty good resource. I'd like to add the following, which I continually reference and has led to repeatable success: https://www.linuxbabe.com/mail-server/setting-up-dkim-and-sp... And as far as confirming it works, I continually rely on sending to a gmail address. Under the three dots is "view original" which gives you SPF, DKIM, and DMARC results. (edit:formatting)
jcul
This is a cool site to visualise your SPF, DKIM, DMARC setup interactively. https://www.learndmarc.com/
duhhhhh1212
https://www.pangram.com/history/8c0a7f5f-3db7-4435-b459-04ae... Don’t waste your time.
jonathanlydall
We generally run on Microsoft 365 and use SendGrid for transactional emails such as password resets. Main domain has SPF set up correctly as per MS docs. We have the CNAME set up for a like em1234 sub-domain as per SendGrid’s docs which their docs say should cover SPF even if the emails we send have a from address of our main domain (eg noreply@example.com), this is apparently because receiving servers are supposed to do SPF checks against the replyTo address which sendgrid does populate with an address on the subdomain. This has worked fine for years, Gmail for example is happy and looking at mails from us says everything passes. However, we recently onboarded a large corporate whose server was blocking the SendGrid emails because it was checking the SPF against the from header rather than the replyTo. Only way to let the email through was to either add SendGrid SPF records to our main domain, or change the from address of the SendGrid emails, neither of which was 100% ideal. Not going to try tell the client they’ve configured their server wrong, but have they?
gerdesj
This was not written by an email admin. Start with the real basics: Your MTA should announce itself and DNS should agree. So your MTA says: HELO smtp.example.co.uk smtp.example.co.uk will resolve to an A record (say a.b.c.d) and a reverse lookup will also work: d.c.b.a.in-addr.arpa PTR smtp.example.co.uk. Remember this is all about reputation, so if you also DNSSEC sign example.co.uk, then you will look like you care about your domain reputation. Then do SPF, DKIM and DMARC. Note how the example for SPF stops at ~all and not -all. The rest is also superficial. Anyway, I run email systems that do the job properly and it is not trivial and certainly not formulaic. There is no shortcut to getting an IP address/range trusted. The advice on that page is ... good as far as it goes but woefully inadequate for running an email system. It's a good start.
albertgoeswoof
This is an aws ses wrapper so is basically irrelevant in the email world