UK IT & website support · plans from £25/month · £45/hour ad-hoc01623 650333 · Client login
Get help

How to Set Up SPF, DKIM and DMARC for Your Domain

To set up SPF, DKIM and DMARC, publish one SPF TXT record listing every service that sends your email, switch on DKIM signing in Microsoft 365 or Google Workspace and add its DNS records, then add a DMARC record starting at p=none. dijitul sets these up and checks them for UK businesses at £45 an hour + VAT.

Updated 2026-10-10 · by the dijitul support team, Mansfield, UK

Key facts

  • SPF lists which servers may send email for your domain, in one TXT record starting v=spf1
  • Microsoft 365's SPF include is include:spf.protection.outlook.com; Google Workspace's is include:_spf.google.com
  • SPF has a limit of 10 DNS lookups; going over it makes SPF fail
  • DKIM adds a digital signature; Microsoft 365 uses two CNAME records, Google Workspace a TXT record
  • DMARC is a TXT record at _dmarc.yourdomain that tells receivers what to do when checks fail
  • Start DMARC at p=none, read the reports, then move to p=quarantine and p=reject
  • dijitul sets up and verifies email authentication at £45 an hour + VAT

What the three records do

  • SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain.
  • DKIM (DomainKeys Identified Mail) signs each message with a private key; receivers check the signature against a public key in your DNS.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) ties them together. It says a message must pass SPF or DKIM with a domain that matches the visible From address, tells receivers what to do if it does not, and sends you reports.

Together they stop criminals spoofing your domain in phishing emails and help your genuine mail avoid the spam folder. Before you start, list every service that sends as your domain: your mailbox provider, newsletter tool, CRM, invoicing system, website and any scanners or printers that email.

Step 1: SPF

In your DNS (at your registrar, host or Cloudflare), create or edit a TXT record on the root of the domain (often shown as @). Typical examples:

  • Microsoft 365 only: v=spf1 include:spf.protection.outlook.com -all
  • Google Workspace only: v=spf1 include:_spf.google.com ~all
  • Microsoft 365 plus a marketing tool: v=spf1 include:spf.protection.outlook.com include:[the tool's include] -all

Rules that catch people out: you can only have one SPF record, so merge rather than add a second. Each include counts towards a limit of 10 DNS lookups, and going over makes SPF fail. -all is a hard fail for anything not listed; ~all is a softer fail. With DMARC in place either works, but never use +all.

Step 2: DKIM

Microsoft 365: in the Microsoft Defender portal, go to Email and collaboration, Policies and rules, Threat policies, Email authentication settings, then the DKIM tab. Select your domain. Microsoft shows two CNAME records, for selector1._domainkey and selector2._domainkey. Copy the values exactly into your DNS, wait for them to resolve, then switch on 'Sign messages for this domain with DKIM signatures'.

Google Workspace: in the Admin console, go to Apps, Google Workspace, Gmail, Authenticate email. Generate a 2048-bit key, publish the TXT record it gives you at google._domainkey, wait for DNS, then click Start authentication.

Do the same in every third-party sender: most give you CNAME or TXT records to prove they can sign as your domain.

Step 3: DMARC

Add a TXT record with the host name _dmarc. Start in monitoring mode:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.uk

Receivers then send daily XML reports showing every server sending as your domain and whether it passed. A DMARC report tool makes these readable. When the reports show all genuine mail passing, tighten the policy to p=quarantine (failures go to spam), then p=reject (failures are refused). Moving straight to reject without monitoring is how businesses accidentally block their own invoices.

For domains that never send email, publish v=spf1 -all and v=DMARC1; p=reject so criminals cannot use them.

Step 4: test it

Send a message to a Gmail address and use Show original: SPF, DKIM and DMARC should all say PASS. Free checkers such as MXToolbox will also validate the syntax and count SPF lookups. DNS changes usually appear within an hour, though some take longer depending on the record's TTL. If mail still lands in junk after everything passes, see why emails go to spam for other causes.

Keep a simple note of every record you added and why. When you later add a new tool, such as a booking system that sends confirmations, you will know to update SPF and DKIM before it goes live.

When to call dijitul

Call us if you have several services sending as your domain, an SPF record over the lookup limit, a Microsoft 365 tenant with multiple domains, or DMARC reports you cannot make sense of. We map every sender, set up the records, step DMARC up safely and check the results, at £45 an hour + VAT. See email security and domain and DNS support, or contact us.

Frequently asked questions

What is the SPF record for Microsoft 365?

For a domain that only sends through Microsoft 365, the SPF record is a TXT record on the root of the domain: v=spf1 include:spf.protection.outlook.com -all. If other services also send as your domain, add their include statements before the -all, keeping a single SPF record.

Can I have two SPF records?

No. A domain must have only one SPF record. If there are two, receivers treat SPF as a permanent error and it fails. Merge all the include statements into one record, and keep the total DNS lookups at 10 or fewer.

What DMARC policy should I start with?

Start with p=none and a rua reporting address, so you can see who is sending as your domain without affecting delivery. Once reports show genuine mail passing, move to p=quarantine and then p=reject. Jumping straight to reject risks blocking your own legitimate email.

How do I turn on DKIM in Microsoft 365?

In the Microsoft Defender portal, open Email and collaboration, Policies and rules, Threat policies, Email authentication settings, then DKIM. Select your domain, publish the two CNAME records it shows in your DNS, wait for them to resolve, then enable DKIM signing for the domain.

Do I need SPF, DKIM and DMARC if I am a small business?

Yes. Without them, receiving servers have no way to prove your email is genuine, which pushes it towards spam, and criminals can easily spoof your domain. Setting all three up is usually a short job. dijitul does it at £45 an hour + VAT.

How long do SPF, DKIM and DMARC changes take to work?

Most DNS changes take effect within an hour, although it depends on the record's TTL and your DNS provider. DKIM in Microsoft 365 cannot be enabled until the CNAME records resolve. DMARC reports start arriving from receivers within a day or two.

Related

Get it fixed

One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.

Call usGet help now