What are SPF, DKIM and DMARC, and does my business need them?
The short answer: yes, almost certainly. SPF, DKIM and DMARC are three settings on your domain that prove your emails really come from you. They make it much harder for criminals to send fake emails in your name, and the big email providers increasingly expect them, so without them your genuine emails are more likely to end up in junk.
What each one does
Think of sending an email like posting a letter. These three checks help the person receiving it decide whether it's genuine.
- SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. It's like telling the post office "only these vans deliver our letters".
- DKIM (DomainKeys Identified Mail) adds a digital signature to every email you send. The receiving server checks the signature, which proves the email came from your domain and wasn't changed on the way.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) is your instruction to the world about what to do with emails that fail those checks: let them through, put them in junk, or reject them. It also lets you receive reports showing who is sending email using your domain.
All three are added as records in your domain's DNS, usually at the company where you bought your domain.
Why your business needs them
- Stopping spoofing. Without them, anyone can send an email that appears to come from accounts@yourbusiness.co.uk. That's how a lot of invoice fraud starts, with your customers as the target.
- Getting your email delivered. Since 2024, Google and Yahoo have required SPF, DKIM and DMARC from bulk senders, and Microsoft brought in similar rules for high-volume senders to Outlook.com and Hotmail in 2025. Even if you're not a bulk sender, providers treat email without these checks with more suspicion, so it's more likely to land in junk.
- Looking trustworthy. Customers, insurers and security questionnaires increasingly ask about them.
Setting up SPF for Microsoft 365
SPF is a single TXT record on your domain. If Microsoft 365 is the only thing that sends email as your domain, it's usually:
v=spf1 include:spf.protection.outlook.com -all
Most businesses have other senders too, such as Mailchimp, Xero, a website contact form or a booking system. Each one needs adding to the same record, usually with its own "include". Check each provider's help pages for the right value. Two rules to remember:
- You can only have one SPF record per domain. Combine everything into it.
- The -all at the end means "reject anything else", so leaving out a genuine sender can stop its emails arriving.
Setting up DKIM for Microsoft 365
DKIM is switched on in Microsoft Defender, usually under Email & collaboration > Policies & rules > Threat policies > Email authentication settings, on the DKIM tab.
- Select your domain.
- Microsoft shows you two CNAME records, usually named selector1._domainkey and selector2._domainkey.
- Add both at your DNS host.
- Wait a little, then switch DKIM on for the domain.
Other services that send as your domain, like Mailchimp, usually have their own DKIM setup too.
Setting up DMARC, one step at a time
DMARC is a TXT record called _dmarc on your domain. Don't jump straight to blocking things. Go in stages:
- Monitor. Start with p=none and an address for reports, for example v=DMARC1; p=none; rua=mailto:dmarc@yourbusiness.co.uk. Nothing is blocked; you just collect reports. A free or low-cost DMARC reporting service makes them readable.
- Quarantine. Once the reports show all your genuine senders passing, change to p=quarantine. Fakes go to junk.
- Reject. When you're confident, move to p=reject. Fakes are refused completely.
Rushing to reject before you've found all your senders is the classic way to stop your own invoices arriving.
Check your current setup
Free online tools such as MXToolbox or the checkers from DMARC reporting companies will show what records your domain has right now. Type in your domain and look for SPF, DKIM and DMARC results. Our free Microsoft 365 audit checks them too, along with your other security settings.
Common questions
Will this stop all phishing emails?
No. It stops criminals faking your exact domain. They can still use lookalike domains, such as yourbusiness-uk.com, or send from a hacked account. See how to know if your email has been hacked.
We're a tiny business. Do we really need this?
Yes. Small businesses are targeted precisely because they're less likely to have these set up. The records cost nothing; they just take a little care to set up correctly.
Could setting these up break our email?
A wrong SPF record or a DMARC policy that's too strict too soon can stop genuine emails arriving. That's why it's worth starting DMARC at p=none and listing every service that sends email for you before tightening things.
Do I need these if I just added my domain to Microsoft 365?
Yes. See how to use your own domain for Microsoft 365 email for the full setup, including where SPF and DKIM fit in.
Want us to check yours?
Our free Microsoft 365 audit looks at your licences, security, email and backups, and tells you in plain English what to fix first. No card, no obligation.