How to Set Up SPF, DKIM, and DMARC for Your Small Business Email (Before the Holiday Rush)
A plain-English, step-by-step guide to authenticating your business email so holiday campaigns and order confirmations land in the inbox, not spam.
If your holiday emails are landing in spam, or not landing at all, the problem often isn't your subject line. It's three DNS records most small businesses set up once, half-finished, years ago: SPF, DKIM, and DMARC.
Gmail, Yahoo, and Microsoft's Outlook.com have all tightened the rules for who gets into the inbox. Bulk senders now need all three records in place, and everyone else is expected to authenticate their mail too. The good news is that this is a one-afternoon job for most businesses. This tutorial walks you through it step by step, in plain English, so your Black Friday and holiday campaigns actually reach customers.
What SPF, DKIM, and DMARC Actually Do
Email was designed decades ago with no built-in way to prove who sent a message. Anyone can type your domain into the "From" line. These three records are how you prove that mail claiming to be from yourbusiness.com really is from you.
- SPF (Sender Policy Framework) is a list of the servers and services allowed to send email for your domain. Think of it as a guest list.
- DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving server checks that signature against a public key in your DNS to confirm the message wasn't forged or altered.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together. It tells inbox providers what to do when a message fails the checks, and it sends you reports about who is sending mail using your domain.
You need all three working together. SPF or DKIM alone leaves gaps. DMARC without the other two has nothing to enforce.
Who Needs This (Hint: Probably You)
Google and Yahoo's formal bulk-sender requirements kick in for domains sending around 5,000 or more messages a day to their users, and Microsoft applied similar rules to Outlook.com and Hotmail addresses in 2025. A lot of small businesses read that number and assume they're exempt.
Here's why you shouldn't:
- All senders are expected to authenticate. Google's guidelines ask every sender to set up at least SPF or DKIM. Mail without authentication is far more likely to be filtered.
- Holiday volume spikes. A list that's small most of the year can cross the bulk threshold during a single Black Friday send.
- Spoofing protection. Without DMARC, scammers can send phishing emails that appear to come from your domain, to your own customers. That's a reputation problem no matter how small you are.
- Your transactional email matters too. Order confirmations, password resets, and invoices from your website or store need to arrive. They go through the same filters.
Before You Start: Make an Inventory of Everything That Sends Email
This is the step people skip, and it's the reason most setups break. Before touching DNS, write down every service that sends email using your domain. For a typical small business, that list looks something like this:
- Your mailbox provider (Google Workspace or Microsoft 365, usually)
- Your email marketing platform (Mailchimp, Klaviyo, Constant Contact, etc.)
- Your ecommerce platform (Shopify, WooCommerce, Square) for order emails
- Your website's contact form or WordPress notifications
- Your CRM, helpdesk, or booking tool (HubSpot, Zendesk, Calendly-style schedulers)
- Your invoicing or accounting software
Check with whoever manages each tool. If a service sends as @yourbusiness.com and you leave it off, it will start failing authentication once you tighten DMARC later.
You'll also need login access to wherever your domain's DNS is managed. That's often your domain registrar (GoDaddy, Namecheap, Squarespace Domains) or a service like Cloudflare. If you're not sure, a free "DNS lookup" tool will show your domain's nameservers, which tells you where the records live.
Step 1: Set Up (or Fix) Your SPF Record
SPF is a single TXT record on your root domain. It lists approved senders using include: statements that each provider gives you in its documentation.
What a typical SPF record looks like
A business using Google Workspace and a marketing platform might have something like:
v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
The pieces:
v=spf1tells servers this is an SPF record.- Each
include:authorizes one provider. Copy these exactly from each provider's help docs. ~all("soft fail") says mail from anyone else is suspicious.-all("hard fail") says reject it outright. Starting with~allis the safer choice while you're testing.
The SPF mistakes that break things
- Two SPF records. You can only have one. If you find two TXT records starting with
v=spf1, merge them into a single record. - Too many lookups. SPF allows a maximum of 10 DNS lookups. Each
include:can trigger several. If you use a lot of tools, you can hit this limit and SPF fails silently. A free SPF checker will count the lookups for you. - Leftovers from old tools. Remove includes for services you no longer use. They waste lookups and widen who can send as you.
Step 2: Turn On DKIM for Every Sending Service
DKIM is set up per service, not once for the whole domain. Each tool that sends on your behalf needs its own DKIM key published in your DNS.
For your mailbox provider
- Google Workspace: In the Admin console, go to Apps, then Google Workspace, then Gmail, then Authenticate email. Generate a new record (choose a 2048-bit key if your DNS host supports it), add the TXT record it gives you to DNS, then come back and click "Start authentication."
- Microsoft 365: In the Microsoft Defender portal, find the DKIM settings under email authentication. Microsoft gives you two CNAME records to add to DNS. Once they're published, enable DKIM signing for your domain.
Menu names shift from time to time, so if something has moved, search your provider's help center for "set up DKIM."
For your marketing and ecommerce tools
Look for a setting called "domain authentication," "authenticate your domain," or "sender authentication" in each platform. Most give you two or three CNAME records to add. Until you do this, many platforms sign your mail with their domain instead of yours, which causes the alignment problem covered below.
Use 2048-bit keys where possible
Longer keys are harder to crack. Most modern providers default to 2048-bit. If yours offers a choice, take the longer one.
Step 3: Publish a DMARC Record (Start in Monitoring Mode)
DMARC is a TXT record on a special subdomain: _dmarc.yourbusiness.com. Start with a policy that only watches and reports, so you don't accidentally block your own legitimate mail.
A starter record looks like this:
v=DMARC1; p=none; rua=mailto:[email protected]
p=nonemeans "don't block anything yet, just report." This is the minimum the major inbox providers accept for bulk senders.rua=is where daily aggregate reports get sent. Use a dedicated mailbox or a DMARC reporting service, because the reports arrive as XML files that aren't fun to read by hand.
Reading DMARC reports without losing your mind
Raw DMARC reports are technical. Several services offer free or low-cost tiers that turn them into a readable dashboard showing which sources are sending as your domain and whether they pass. For a small business, a free tier is usually plenty. What you're looking for is simple: every service from your inventory should show as passing, and anything you don't recognize is either a tool you forgot or someone spoofing you.
Step 4: Check Alignment (The Step Everyone Misses)
This is where most "but I set it all up!" frustration comes from. A message can pass SPF and pass DKIM and still fail DMARC.
Why? DMARC requires alignment: the domain that passed SPF or DKIM must match the domain in the visible "From" address. If your newsletter says it's from [email protected] but DKIM was signed by your email platform's own domain, DKIM passes, but it doesn't count for DMARC.
To fix it:
- Complete the domain authentication step inside each sending tool (Step 2), so DKIM is signed with your domain.
- Where a tool supports a custom return-path or "bounce domain," set that up too, so SPF aligns as well.
- Send a test email to a Gmail address, open it, and choose "Show original." You want to see PASS next to SPF, DKIM, and DMARC.
Rule of thumb: DMARC only needs SPF or DKIM to pass and align. DKIM is the more reliable of the two, because it survives email forwarding and SPF often doesn't. Make sure every tool signs with your domain.
Step 5: Tighten Your Policy Over a Few Weeks
Once your reports show that all your legitimate mail passes consistently, move your policy toward enforcement. That's what actually stops spoofers.
- Weeks 1–3:
p=none. Watch reports. Fix any of your own services that fail. - Next:
p=quarantine. Failing mail goes to spam instead of the inbox. You can ease in usingpct=25to apply it to a portion of failing mail first, then raise it. - Finally:
p=reject. Failing mail is blocked outright. This is the strongest protection for your brand.
Don't rush this during peak season. If you're starting in mid-October, getting to p=none with clean, aligned reports before Black Friday is a solid goal. Save the move to quarantine and reject for a quieter stretch in January, when an unexpected failure won't cost you holiday orders.
Step 6: Cover the Other Inbox Requirements
Authentication gets you through the door. A few other rules decide whether you stay there, especially if you send marketing email:
- One-click unsubscribe. Bulk senders to Gmail and Yahoo must support one-click unsubscribe in the email header, and honor requests promptly. Reputable email platforms handle this for you, but confirm it's turned on.
- Keep spam complaints low. Google says senders should keep their reported spam rate below 0.3%, and recommends staying well under that. You can monitor it in Google Postmaster Tools, which is free.
- Only email people who opted in. Purchased lists and old, unengaged contacts drive complaints up. Clean your list before the holiday push.
- Use your own domain in the From line. Sending marketing mail from a free Gmail or Yahoo address is a fast route to the spam folder.
How to Test That Everything Works
Before your first big holiday send, run through this quick checklist:
- Look up your domain with a free SPF, DKIM, and DMARC checker. All three should be found and valid.
- Confirm you have exactly one SPF record and it stays under 10 lookups.
- Send a test from each service on your inventory (mailbox, newsletter, store, contact form) to a Gmail address and check "Show original" for three passes.
- Sign up for Google Postmaster Tools and verify your domain so you can watch reputation and spam rate during the season.
- Confirm DMARC reports are arriving and every known sender shows as passing.
Common Questions
Will setting up DMARC break my email?
Not if you start with p=none. That policy only collects reports. Problems happen when businesses jump straight to p=reject before confirming every sending service is aligned.
Do I need a developer for this?
Not necessarily. If you're comfortable editing DNS records and following provider instructions, you can do it yourself. Where it gets tricky is when you have many sending tools, hit the SPF lookup limit, or inherited a messy DNS setup from a previous vendor. That's when a second set of eyes saves time.
How long until changes take effect?
DNS changes usually show up within minutes to a few hours, though some can take up to a day or two to propagate everywhere. Give it time before assuming something is broken.
Get Your Email Ready Before the Rush
Email authentication isn't glamorous, but it's the foundation everything else sits on. The best holiday campaign in the world does nothing if it lands in spam. Spend an afternoon on SPF, DKIM, and DMARC now, and your order confirmations, promos, and follow-ups have a real shot at reaching the people who asked for them.
If you'd rather have someone audit your DNS, untangle a crowded SPF record, or set up authentication across your website, store, and marketing tools, the Kodbee team can help. Get in touch and we'll take a look.