Authentication

Email authentication

SPF, DKIM, DMARC, BIMI, ARC and the DNS records that prove your mail is yours.

How to use this topic

Start with the pillar guide for the full model, follow the diagnostic workflow for the current problem, and use the commercial destination when the evidence needs to become a repeatable team process.

Monitor DMARC and sender authentication

Turn DNS records and aggregate reports into sender inventory, alignment evidence, and an enforcement plan.

Curated guide

Start with identity, not policy

Authentication work should first answer which services are allowed to send, which domains they sign with, and whether those identifiers align with the visible From domain. Policy changes come after the sender map is trustworthy.

Move enforcement only with evidence

Use aggregate reporting to separate legitimate sources from unknown traffic, then raise enforcement in stages. A rushed reject policy can break mail that is business-critical but poorly inventoried.

Cover adjacent authentication layers

BIMI, ARC, MTA-STS, TLS-RPT, and DNSSEC do different jobs. Treat them as supporting evidence around authentication rather than as substitutes for SPF, DKIM, and DMARC alignment.

Diagnostic workflow

  1. Step 1

    Check publication

    Inspect SPF and DMARC records before changing policy.

    Open workflow
  2. Step 2

    Understand alignment

    Separate raw SPF or DKIM pass from DMARC-aligned identity.

    Open workflow
  3. Step 3

    Monitor before enforcing

    Label legitimate and unknown senders before moving toward reject.

    Open workflow

Relevant free tools

  • SPF checker

    Expand mechanisms, count DNS lookups, and identify policy risks.

  • DMARC checker

    Inspect policy, reporting, alignment, and subdomain behavior.

Pillar guide

DMARC rollout: from p=none to p=reject without breaking mail

·5 min read

The exact six-week schedule for moving from monitoring-only DMARC to full enforcement, with the report-reading checkpoints that keep you safe.

Read pillar

Supporting guides

Frequently asked questions

Do SPF and DKIM passing mean DMARC passes?
No. At least one authenticated identifier must also align with the visible From domain.
Should a new domain start with DMARC p=reject?
Usually no. Start with reporting, inventory legitimate senders, correct alignment, then increase enforcement with evidence.