ENB Technologies Log inStart free

Guides › SPF, DKIM and DMARC explained in plain English

SPF, DKIM and DMARC explained in plain English

Updated 2026-09-28

Short answer: SPF, DKIM and DMARC are three DNS records that prove an email really comes from your domain. SPF lists the servers allowed to send for you, DKIM adds a digital signature that shows the email was not changed, and DMARC tells inbox providers what to do if a message fails those checks. Without them, bulk email is far more likely to land in spam.

SPF: who is allowed to send

SPF is a TXT record that lists the services allowed to send email for your domain. Inbox providers check the sending server against this list.

DKIM: a tamper-proof signature

DKIM signs each email with a private key. The matching public key sits in your DNS, so providers can confirm the email came from you and was not altered.

DMARC: the policy and the reports

DMARC connects SPF and DKIM to the address people see in the From line, and tells providers to accept, quarantine or reject mail that fails. It also sends you reports about who is sending as your domain.

Do I need my own domain?

No. If you do not have a domain, ENB sends from its own authenticated domain with your business name. When you add your own domain, ENB shows you the exact records to copy into your DNS and checks them for you.

Frequently asked questions

Do I need all three?

Yes. Gmail and Yahoo require SPF, DKIM and DMARC for bulk senders.

Where do I add these records?

In the DNS settings of your domain, at the company where you bought or host it (for example Cloudflare, Namecheap or your web host).

What DMARC policy should I start with?

Start with p=none to collect reports, then move to quarantine or reject once all your legitimate sending passes.

Related guides

Start free today

Free plan, no card needed. Set up in two minutes with your Gmail or Yahoo address.

Create a free account See pricing