Article content and detailed guides remain in English. The selected language applies to controls and quick instructions.

Back to articles

SPF, DKIM and DMARC Explained: Email Authentication Basics

On this page

Authentication is separate from extraction

Email Extractor finds addresses in supplied content. It does not send campaigns or configure your mail domain. If you later send messages, authentication is one part of the sending system you need to check.

SPF, DKIM and DMARC help receivers evaluate domain identity. They do not establish that recipients want a message, that its content is trustworthy or that it will reach the inbox.

SPF checks the sending path

SPF publishes which hosts may send using a domain in the SMTP envelope or HELO identity. That identity can differ from the visible From address. The SPF specification defines these checks and limits on DNS lookups.

Use the exact configuration documented by your actual mail providers. Do not add a separate SPF record for every tool or assume every outreach application sends through its own servers. Multiple SPF records can cause errors; authorized senders belong in a reviewed configuration.

DKIM checks a domain signature

DKIM lets a signing domain attach a cryptographic signature to selected message content. The receiver checks it using the public key published for the signature's selector.

A valid signature associates signed content with the signing domain; it does not by itself prove the human sender's identity or alignment with the visible From address. See the DKIM specification.

Enable signing through your provider and publish the records it supplies. Selector names are provider-specific; google is not a universal selector for every domain.

DMARC checks alignment and states policy

DMARC ties authentication to the visible From domain. A message can pass DMARC through aligned SPF or aligned DKIM; both do not have to pass for that result.

The domain can request monitoring, quarantine or rejection for failures. Receiver handling can still depend on local policy. Monitoring with p=none is not enforcement, and adding it does not automatically enable reports without report destinations. The DMARC specification explains alignment, policy and reporting.

Before tightening policy, identify every legitimate sending service and review its authentication. A fixed calendar schedule is not a substitute for checking actual traffic.

Inspect DNS and a test message

If dig is installed, these read-only examples inspect records. Replace the example domain and selector with your own values:

dig +short TXT example.com
dig +short TXT selector._domainkey.example.com
dig +short TXT _dmarc.example.com

DNS records alone do not prove outgoing messages use them correctly. Send a test message to a mailbox you control and inspect its Authentication-Results with your mail provider's header viewer. Verify the signing domain, envelope identity and From alignment.

For provider requirements, consult its current documentation. Google's sender requirements FAQ covers Gmail's authentication expectations. Passing authentication is not permission to send an extracted list; review privacy and list use separately.

Extract emails

Explore tools

Verify emails

Check address validity before using your list.

ZeroBounce

Email Verification

Verifies email lists and provides tools for monitoring deliverability.

Useful when list cleaning and sender health belong in one workflow.

Explore ZeroBounce (opens in a new tab)