Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungChrome Already Has The Eyedropper You're Building(20.09.2026 um 18:25 Uhr)
Sichere ProgrammierungFor VS Code lovers, you can have a colored border and more from now...(20.09.2026 um 18:25 Uhr)
Sichere ProgrammierungNuxt Hydration Mismatch: Why It Happens and How to Fix It(20.09.2026 um 18:26 Uhr)
Sichere ProgrammierungYour Browser Is Rejecting Every Drop On Purpose(20.09.2026 um 18:26 Uhr)
Sichere ProgrammierungReact Derived State: Why That useState Is Probably a Bug(20.09.2026 um 18:27 Uhr)
Sichere ProgrammierungI tried OpenProject and Vikunja. Then I built Agila.(20.09.2026 um 18:37 Uhr)
Sichere ProgrammierungSkill Recorder keeps your screen local until you press Analyze(20.09.2026 um 18:38 Uhr)
Sichere ProgrammierungChrome Already Has The Eyedropper You're Building(20.09.2026 um 18:25 Uhr)
Sichere ProgrammierungFor VS Code lovers, you can have a colored border and more from now...(20.09.2026 um 18:25 Uhr)
Sichere ProgrammierungNuxt Hydration Mismatch: Why It Happens and How to Fix It(20.09.2026 um 18:26 Uhr)
Sichere ProgrammierungYour Browser Is Rejecting Every Drop On Purpose(20.09.2026 um 18:26 Uhr)
Sichere ProgrammierungReact Derived State: Why That useState Is Probably a Bug(20.09.2026 um 18:27 Uhr)
Sichere ProgrammierungI tried OpenProject and Vikunja. Then I built Agila.(20.09.2026 um 18:37 Uhr)
Sichere ProgrammierungSkill Recorder keeps your screen local until you press Analyze(20.09.2026 um 18:38 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

SPF, DKIM, DMARC: the 15-minute setup that actually passes

Reagiere als Erste:r — dein Feedback zählt!

Every guide to email authentication starts with a history lesson. Skip it. You are here because your emails land in spam, or a client asked "is DMARC set up?", or you saw dmarc=fail in a bounced message. Here is the 15-minute version: the exact records, why each one exists in one sentence, and how to verify you got it right.

The one-sentence versions

  • SPF lists which servers may send mail claiming to be from your domain.
  • DKIM cryptographically signs each message so receivers can verify it was not altered and really came from you.
  • DMARC tells receivers what to do when SPF or DKIM fail, and sends you reports about it.

SPF and DKIM are the mechanisms. DMARC is the policy on top. You need all three.

SPF: one TXT record

At your domain root (or the subdomain you send from), add a TXT record:

v=spf1 include:_spf.yourprovider.com ~all

Replace the include with whatever your email provider documents. Sending through Amazon SES it is include:amazonses.com; Google Workspace is include:_spf.google.com. If you send through several providers, chain the includes in a single record:

v=spf1 include:amazonses.com include:_spf.google.com ~all

Mistake #1: two SPF records. SPF allows exactly one TXT record starting with v=spf1 per domain. Two records means SPF returns a permanent error, which is worse than no record at all. Merge them.

Also know the 10-DNS-lookup limit: every include costs lookups, and past 10 the check fails. If you have collected includes from years of tools, prune them.

Verify it with dig:

dig +short TXT yourdomain.com | grep spf1

or use a checker that also counts your lookups, like this free SPF checker.

DKIM: the CNAMEs your provider gives you

You do not write DKIM records by hand. Your provider generates a key pair, keeps the private key, and gives you DNS records (usually 1 to 3 CNAMEs) that publish the public key. They look like:

abc123._domainkey.yourdomain.com  CNAME  abc123.dkim.provider.com

Add them exactly as given and wait for verification. That is it.

Mistake #2: proxying the DKIM CNAMEs. If your DNS is behind Cloudflare, those records must be DNS only (grey cloud). Proxied CNAMEs resolve to Cloudflare IPs and DKIM verification never completes. This one costs people days.

Verify with the selector your provider used:

dig +short TXT abc123._domainkey.yourdomain.com

You should see a v=DKIM1; k=rsa; p=... blob. A DKIM checker does the same with the parsing done for you.

DMARC: start monitoring, then enforce

Add a TXT record at _dmarc.yourdomain.com:

v=DMARC1; p=none; rua=mailto:[email protected]

p=none means "change nothing, just send me aggregate reports about who is sending as my domain." Run in this mode for a couple of weeks and read the reports; you will usually discover a forgotten tool sending as your domain.

Then enforce:

v=DMARC1; p=quarantine; rua=mailto:[email protected]; pct=100

and eventually p=reject. Enforcement is what actually stops spoofing, and since 2024 Gmail and Yahoo require a DMARC record for bulk senders at all.

Mistake #3: jumping straight to p=reject. If some legitimate system sends unaligned mail (a CRM, a billing tool, an old cron job), p=reject silently kills those messages. Monitor first, enforce second.

Verify:

dig +short TXT _dmarc.yourdomain.com

or decode the policy in plain English with a DMARC analyzer.

The 15-minute checklist

  1. One SPF record, correct include, ~all at the end. Check the lookup count.
  2. Add the provider's DKIM CNAMEs, unproxied. Confirm the selector resolves.
  3. _dmarc record at p=none with a rua address. Calendar reminder for two weeks: read reports, move to quarantine, then reject.
  4. Send a test email to a Gmail account, open "Show original", and confirm all three lines say PASS.

Step 4 is the ground truth. Gmail's "Show original" view shows spf=pass dkim=pass dmarc=pass right at the top, and it is checking the real thing rather than just the DNS.

Once these pass, deliverability problems stop being an authentication problem and start being a reputation problem. That is a different article, but you cannot get there without this one.

While speaking of emails, if you want to learn how SMTP works under the hood, watch a message move from application code to an SMTP relay, through TLS and AUTH, across DNS and recipient MX checks, and finally into a mailbox check out this simulator: SMTP Flow Simulator

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SPF, DKIM, DMARC: the 15-minute setup that actually passes

Thematisch verwandte Begriffe: DKIM, DMARC, 15minute, setup · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick