# Business Email Authentication: SPF, DKIM, and DMARC

<!-- Generated by scripts/generate-public-markdown.ts. Do not edit directly. -->

> Set up SPF, DKIM, and DMARC so form alerts, quotes, and review requests sent from your domain reach inboxes instead of spam.

Canonical: https://vassalmarketing.com/information/website-stewardship/business-email-authentication/

**Maintained by Vassal Marketing** · Last updated on September 26, 2026

Reviewed at least quarterly and whenever a platform or rule it cites changes.

General information, not legal or professional advice. Check rules that affect your business with a qualified professional.

If quotes, form alerts, or review requests from your business land in spam, the fix is often three DNS records: SPF, DKIM, and DMARC. Ask your provider to list every service that sends email as your business, publish those records, and start DMARC in monitoring mode.

## Why this matters

Gmail, Yahoo, and Outlook.com check incoming mail for proof that the sender may use the domain. Mail without that proof is more likely to land in spam or be rejected. This affects more than newsletters. Website form alerts, quotes, invoices, and review-request emails are often sent by outside services using your domain.

The proof lives in DNS, the settings that direct your domain's traffic. SPF lists the services allowed to send as you. DKIM adds a digital signature to each message. DMARC tells receiving providers what to do when a message fails those checks, and sends you reports. Your provider can set up all three; you mainly need to know which tools send email for the business.

## Responsible practices

### List every service that sends as your business

Include your mailbox provider, website form, booking tool, invoicing or customer-management software, and any review-request or newsletter service. Each one needs to pass SPF or DKIM. A forgotten sender is the usual reason authenticated mail still fails.

### SPF: the approved-sender list

SPF (Sender Policy Framework) is one DNS text record listing which services may send email for your domain. Your domain should have only one SPF record. When you add a sending service, update that record rather than creating a second one.

### DKIM: a signature on each message

DKIM (DomainKeys Identified Mail) adds a signature that receiving servers check against a key published in your DNS. Most email and marketing services give you DKIM records to add. Turn it on for every service that supports it, not just your main mailbox.

### DMARC: start by watching

DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells receivers what to do with mail that fails SPF and DKIM. It also sends reports showing who is sending as your domain. Start with p=none, which only monitors. Once every real sender passes, your provider can move to p=quarantine (failures go to spam), and later p=reject.

### Know the mailbox providers' rules

Since February 2024, Google and Yahoo have required every sender to use SPF or DKIM. Bulk senders, which Google defines as close to 5,000 or more messages a day to Gmail accounts, must use SPF, DKIM, and DMARC and offer one-click unsubscribe on marketing mail. Since May 2025, Outlook.com has applied similar rules to high-volume senders. Most small businesses send far less, but the basic rule still applies.

## Worked example: Why a form alert landed in spam

Hypothetical example: a plumbing company's website form emails the office for each new request. Staff start finding those alerts in the spam folder.

### What the provider found

The form sent mail "from" the business domain through the web host's server. That server was not in the SPF record, and the messages had no DKIM signature.

### The fix

The provider set the form to send through the business's email service, which already passed SPF and DKIM. No second SPF record was added.

### Adding DMARC

The provider published a DMARC record at p=none, with reports going to a reporting tool the office manager checks. The first reports showed the invoicing software also sending unauthenticated mail.

### Tightening later

After both senders passed for several weeks, the provider moved the policy to p=quarantine and kept watching the reports.

Most delivery problems come from a sender nobody listed. Update the sender list whenever you add a tool that emails customers.

## Email authentication checklist

### What you can check

1. List every tool that sends email using your business domain.
2. Send a test message to a Gmail address and check whether it reaches the inbox.
3. Ask your provider whether SPF, DKIM, and DMARC cover each sender.
4. Choose who receives DMARC reports, or which reporting service reads them for you.

### What to ask your provider to handle

1. Publish or correct one SPF record that covers every approved sending service.
2. Turn on DKIM signing for the mailbox provider and each outside service that sends as the business.
3. Publish a DMARC record at p=none, review the reports, and recommend when to tighten the policy.

## Avoid these failures

- Adding a second SPF record instead of updating the existing one.
- Jumping straight to p=reject before every real sender passes.
- Forgetting booking, invoicing, or review-request tools that send as the business.
- Sending DMARC reports to an inbox nobody reads.

Good website care lowers risk, but no provider can guarantee uninterrupted service.

## Questions business owners ask

### Do we need this if we only send a few emails a day?

Yes. Google and Yahoo expect every sender to use SPF or DKIM, and DMARC makes it harder for others to send fake email in your name. Setup is usually a one-time job with updates when you add a tool.

### Why do our website form alerts go to spam?

Often the form sends mail "from" your domain through a server that isn't in your SPF record and doesn't sign with DKIM. Ask your provider to send form mail through an authenticated email service.

### Will DMARC block our own mail?

Not at p=none, which only reports. Problems appear when the policy is tightened before every legitimate sender passes. That is why you start by monitoring.

### Does authentication guarantee inbox delivery?

No. It shows the mail really comes from you. Content, sending volume, and spam complaints also affect where messages land.

## Primary guidance

- [Google Workspace Admin Help: Email sender guidelines](https://support.google.com/a/answer/81126)
- [Yahoo Sender Hub: Sender best practices and requirements](https://senders.yahooinc.com/best-practices/)
- [Microsoft: Outlook's new requirements for high-volume senders](https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730)
- [FTC: Cybersecurity for small business, including email authentication](https://www.ftc.gov/business-guidance/small-businesses/cybersecurity)

## Connected guidance

- [Forms, calls, and booking paths](https://vassalmarketing.com/information/website-stewardship/forms-calls-and-booking-paths.md): Test that customer requests reach the right people and can be answered.
- [Small-business website security](https://vassalmarketing.com/information/website-stewardship/small-business-website-security.md): Protect the accounts behind your site and plan a response to suspicious activity.
- [Responsible review requests](https://vassalmarketing.com/information/reviews-reputation/responsible-review-requests.md): Ask customers for reviews in ways that follow platform rules.
