# How to Set Up SPF, DKIM and DMARC for Your Domain

Source: https://dijitulsupport.co.uk/guides/set-up-spf-dkim-dmarc/
Updated: 2026-10-10

> To set up SPF, DKIM and DMARC, publish one SPF TXT record listing every service that sends your email, switch on DKIM signing in Microsoft 365 or Google Workspace and add its DNS records, then add a DMARC record starting at p=none. dijitul sets these up and checks them for UK businesses at £45 an hour + VAT.

## Key facts

- SPF lists which servers may send email for your domain, in one TXT record starting v=spf1
- Microsoft 365's SPF include is include:spf.protection.outlook.com; Google Workspace's is include:_spf.google.com
- SPF has a limit of 10 DNS lookups; going over it makes SPF fail
- DKIM adds a digital signature; Microsoft 365 uses two CNAME records, Google Workspace a TXT record
- DMARC is a TXT record at _dmarc.yourdomain that tells receivers what to do when checks fail
- Start DMARC at p=none, read the reports, then move to p=quarantine and p=reject
- dijitul sets up and verifies email authentication at £45 an hour + VAT

## What the three records do

- **SPF** (Sender Policy Framework) is a list of the servers allowed to send email for your domain.
- **DKIM** (DomainKeys Identified Mail) signs each message with a private key; receivers check the signature against a public key in your DNS.
- **DMARC** (Domain-based Message Authentication, Reporting and Conformance) ties them together. It says a message must pass SPF or DKIM with a domain that matches the visible From address, tells receivers what to do if it does not, and sends you reports.

Together they stop criminals spoofing your domain in phishing emails and help your genuine mail avoid the spam folder. Before you start, list every service that sends as your domain: your mailbox provider, newsletter tool, CRM, invoicing system, website and any scanners or printers that email.

## Step 1: SPF

In your DNS (at your registrar, host or Cloudflare), create or edit a TXT record on the root of the domain (often shown as @). Typical examples:

- Microsoft 365 only: **v=spf1 include:spf.protection.outlook.com -all**
- Google Workspace only: **v=spf1 include:_spf.google.com ~all**
- Microsoft 365 plus a marketing tool: **v=spf1 include:spf.protection.outlook.com include:[the tool's include] -all**

Rules that catch people out: you can only have **one** SPF record, so merge rather than add a second. Each *include* counts towards a limit of **10 DNS lookups**, and going over makes SPF fail. *-all* is a hard fail for anything not listed; *~all* is a softer fail. With DMARC in place either works, but never use *+all*.

## Step 2: DKIM

**Microsoft 365:** in the Microsoft Defender portal, go to Email and collaboration, Policies and rules, Threat policies, Email authentication settings, then the DKIM tab. Select your domain. Microsoft shows two CNAME records, for *selector1._domainkey* and *selector2._domainkey*. Copy the values exactly into your DNS, wait for them to resolve, then switch on 'Sign messages for this domain with DKIM signatures'.

**Google Workspace:** in the Admin console, go to Apps, Google Workspace, Gmail, Authenticate email. Generate a 2048-bit key, publish the TXT record it gives you at *google._domainkey*, wait for DNS, then click Start authentication.

Do the same in every third-party sender: most give you CNAME or TXT records to prove they can sign as your domain.

## Step 3: DMARC

Add a TXT record with the host name **_dmarc**. Start in monitoring mode:

**v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.uk**

Receivers then send daily XML reports showing every server sending as your domain and whether it passed. A DMARC report tool makes these readable. When the reports show all genuine mail passing, tighten the policy to *p=quarantine* (failures go to spam), then *p=reject* (failures are refused). Moving straight to reject without monitoring is how businesses accidentally block their own invoices.

For domains that never send email, publish **v=spf1 -all** and **v=DMARC1; p=reject** so criminals cannot use them.

## Step 4: test it

Send a message to a Gmail address and use Show original: SPF, DKIM and DMARC should all say PASS. Free checkers such as MXToolbox will also validate the syntax and count SPF lookups. DNS changes usually appear within an hour, though some take longer depending on the record's TTL. If mail still lands in junk after everything passes, see why emails go to spam for other causes.

Keep a simple note of every record you added and why. When you later add a new tool, such as a booking system that sends confirmations, you will know to update SPF and DKIM before it goes live.

## When to call dijitul

Call us if you have several services sending as your domain, an SPF record over the lookup limit, a Microsoft 365 tenant with multiple domains, or DMARC reports you cannot make sense of. We map every sender, set up the records, step DMARC up safely and check the results, at £45 an hour + VAT. See email security and domain and DNS support, or contact us.

## FAQs

### What is the SPF record for Microsoft 365?

For a domain that only sends through Microsoft 365, the SPF record is a TXT record on the root of the domain: v=spf1 include:spf.protection.outlook.com -all. If other services also send as your domain, add their include statements before the -all, keeping a single SPF record.

### Can I have two SPF records?

No. A domain must have only one SPF record. If there are two, receivers treat SPF as a permanent error and it fails. Merge all the include statements into one record, and keep the total DNS lookups at 10 or fewer.

### What DMARC policy should I start with?

Start with p=none and a rua reporting address, so you can see who is sending as your domain without affecting delivery. Once reports show genuine mail passing, move to p=quarantine and then p=reject. Jumping straight to reject risks blocking your own legitimate email.

### How do I turn on DKIM in Microsoft 365?

In the Microsoft Defender portal, open Email and collaboration, Policies and rules, Threat policies, Email authentication settings, then DKIM. Select your domain, publish the two CNAME records it shows in your DNS, wait for them to resolve, then enable DKIM signing for the domain.

### Do I need SPF, DKIM and DMARC if I am a small business?

Yes. Without them, receiving servers have no way to prove your email is genuine, which pushes it towards spam, and criminals can easily spoof your domain. Setting all three up is usually a short job. dijitul does it at £45 an hour + VAT.

### How long do SPF, DKIM and DMARC changes take to work?

Most DNS changes take effect within an hour, although it depends on the record's TTL and your DNS provider. DKIM in Microsoft 365 cannot be enabled until the CNAME records resolve. DMARC reports start arriving from receivers within a day or two.

## Pricing and contact

Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Plans: Essential £25/month + VAT (Website software updates (core, plugins, themes) applied and checked, Daily backups, Uptime monitoring, Security monitoring); Business £50/month + VAT (Everything in Essential, 1 hour of fixes or changes every month, Priority support); Complete £99/month + VAT (Everything in Business, 3 hours of fixes or changes every month, IT and Microsoft 365 helpdesk for your team). Ad-hoc support is £45 an hour + VAT. The first 30 minutes are the minimum charge, then we bill in 15-minute blocks. Contact: 01623 650333, support@dijitul.uk, https://dijitulsupport.co.uk/contact/
