SPF, DKIM and DMARC Explained: Email Authentication Basics
On this page
Authentication is separate from extraction
Email Extractor finds addresses in supplied content. It does not send campaigns or configure your mail domain. If you later send messages, authentication is one part of the sending system you need to check.
SPF, DKIM and DMARC help receivers evaluate domain identity. They do not establish that recipients want a message, that its content is trustworthy or that it will reach the inbox.
SPF checks the sending path
SPF publishes which hosts may send using a domain in the SMTP envelope or HELO identity. That identity can differ from the visible From address. The SPF specification defines these checks and limits on DNS lookups.
Use the exact configuration documented by your actual mail providers. Do not add a separate SPF record for every tool or assume every outreach application sends through its own servers. Multiple SPF records can cause errors; authorized senders belong in a reviewed configuration.
DKIM checks a domain signature
DKIM lets a signing domain attach a cryptographic signature to selected message content. The receiver checks it using the public key published for the signature's selector.
A valid signature associates signed content with the signing domain; it does not by itself prove the human sender's identity or alignment with the visible From address. See the DKIM specification.
Enable signing through your provider and publish the records it supplies. Selector names are provider-specific; google is not a universal selector for every domain.
DMARC checks alignment and states policy
DMARC ties authentication to the visible From domain. A message can pass DMARC through aligned SPF or aligned DKIM; both do not have to pass for that result.
The domain can request monitoring, quarantine or rejection for failures. Receiver handling can still depend on local policy. Monitoring with p=none is not enforcement, and adding it does not automatically enable reports without report destinations. The DMARC specification explains alignment, policy and reporting.
Before tightening policy, identify every legitimate sending service and review its authentication. A fixed calendar schedule is not a substitute for checking actual traffic.
Inspect DNS and a test message
If dig is installed, these read-only examples inspect records. Replace the example domain and selector with your own values:
dig +short TXT example.com
dig +short TXT selector._domainkey.example.com
dig +short TXT _dmarc.example.com
DNS records alone do not prove outgoing messages use them correctly. Send a test message to a mailbox you control and inspect its Authentication-Results with your mail provider's header viewer. Verify the signing domain, envelope identity and From alignment.
For provider requirements, consult its current documentation. Google's sender requirements FAQ covers Gmail's authentication expectations. Passing authentication is not permission to send an extracted list; review privacy and list use separately.