{"id":13465,"date":"2026-10-06T07:35:00","date_gmt":"2026-10-06T05:35:00","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/?p=13465"},"modified":"2026-09-25T09:45:52","modified_gmt":"2026-09-25T07:45:52","slug":"spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one","status":"publish","type":"post","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/","title":{"rendered":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email"},"content":{"rendered":"<p>Any name can be written on an envelope. Email works the same way: the sender address in a message is a line of text, written by whoever sends it, and nothing in the protocol requires it to be true.<\/p>\n<p>Three DNS records exist to deal with this. Two of them are checks. Only one is an instruction &#8211; and that difference decides whether a forged message in a domain&#8217;s name arrives or bounces.<\/p>\n<figure class=\"lw-diagram\">\n<img decoding=\"async\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/diagrams\/spf-dkim-dmarc-en.png\" width=\"1120\" height=\"580\" loading=\"lazy\" alt=\"A message passes three checkpoints: SPF and DKIM answer a question each, DMARC is the only one that issues an instruction to reject\"><figcaption>All three see the same message. Only the third one can act on what it sees.<\/figcaption><\/figure>\n<h2>What SPF, DKIM and DMARC each are<\/h2>\n<p><strong>SPF is a list of servers.<\/strong> The domain owner publishes which machines are allowed to send mail in that domain&#8217;s name. A receiving mail server compares the sending machine against the list and gets a yes or a no.<\/p>\n<p><strong>DKIM is a signature.<\/strong> The sending server signs the message with a private key; the matching public key sits in DNS. If the signature still fits when the message arrives, nothing was altered on the way and it really came from a system holding that key.<\/p>\n<p><strong>DMARC is an instruction.<\/strong> It says what should happen when the first two fail: let the message through anyway, put it in the spam folder, or reject it outright.<\/p>\n<p>That is the whole architecture. Two questions and one answer to them. What surprises most people is which part is missing on most domains &#8211; it is the third.<\/p>\n<h2>Why SPF alone stops nothing<\/h2>\n<p>An SPF check produces a result. It does not produce a consequence.<\/p>\n<p>The receiving server learns that the sending machine is not on the list. What it does with that knowledge is entirely up to the receiving server, and without further instruction most of them do the cautious thing: deliver, perhaps with a marker. Rejecting a legitimate message is far worse for a mail provider than accepting a forged one, so in doubt they accept.<\/p>\n<p>SPF records themselves say something about this. A record can end in <code>-all<\/code>, meaning &#8220;everything else is a forgery&#8221;, or in <code>~all<\/code>, meaning &#8220;everything else is suspicious&#8221;. The second is a request for leniency, and it is what the majority of domains publish &#8211; often because it was the default in a setup guide, not because anyone decided it.<\/p>\n<p>DKIM has the same limit. A failed signature is a finding, not a verdict.<\/p>\n<h2>The hidden budget: ten lookups and no more<\/h2>\n<p>SPF has a limit that catches a lot of domains out, because nothing about it is visible in the record itself.<\/p>\n<p>A record may refer to other records. <code>include:_spf.google.com<\/code> means &#8220;everything that entry allows counts here too&#8221;. Convenient, and it is how mailing services get added. But every such reference costs a DNS lookup, the referenced record may refer onward, and the total is capped at ten.<\/p>\n<p>Beyond ten, the check does not merely fail &#8211; it ends in a permanent error, and by the rules the whole record then counts for nothing. Every entry in it, including the servers that were listed correctly.<\/p>\n<p>The catch is that this cap can be crossed without touching the record. A mailing provider adds one referral inside its own entry, that entry now costs one lookup more, and a domain that sat at ten quietly sits at eleven. Nothing on the domain changed. The check simply stops working.<\/p>\n<p>A well-known payment provider currently sits at nine of ten. That is not carelessness &#8211; it is what a company with many mailing systems ends up with, and it is one referral away from failing.<\/p>\n<figure class=\"lw-illu\">\n<img decoding=\"async\" src=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/illustrationen\/illu-spf-dkim-dmarc.webp\" width=\"1120\" height=\"580\" loading=\"lazy\" alt=\"Three doorways in a row: the first two are open frames, the third is closed\"><br \/>\n<\/figure>\n<h2>How long a DKIM key has to be<\/h2>\n<p>A DKIM key can be found and read, and its length is worth reading.<\/p>\n<p>1024 bits was the standard for years and is still widespread. It is no longer considered adequate; 2048 is the current recommendation. The key is not secret &#8211; the public half sits in DNS for anyone to fetch &#8211; and a key that can be broken lets someone else produce signatures that check out.<\/p>\n<p>There is a second reason short keys survive: a 2048-bit key does not fit in a DNS record in one piece and has to be split. That works, but it is a step that gets skipped, and the old key stays.<\/p>\n<p>One honest limit belongs here. DKIM keys sit under a selector, a name chosen freely by whoever set it up, and DNS offers no way to list the selectors a domain uses. Any check from outside can only try common names &#8211; <code>default<\/code>, <code>google<\/code>, <code>selector1<\/code>, <code>s1<\/code> and a few dozen more. A domain whose selector is not among them shows no keys, and that means &#8220;none found here&#8221;, never &#8220;none exist&#8221;.<\/p>\n<h2>Why most domains stop at p=none<\/h2>\n<p>DMARC is the only one of the three that can order a rejection, and it is the one most domains never finish setting up.<\/p>\n<p>A DMARC record contains a policy: <code>p=none<\/code>, <code>p=quarantine<\/code> or <code>p=reject<\/code>. Only the last one actually turns messages away. <code>p=none<\/code> means: check, report, deliver anyway.<\/p>\n<p><code>p=none<\/code> is the right place to start. Reports arrive, the picture of who sends in the domain&#8217;s name fills in, and forgotten systems surface &#8211; the invoicing tool, the newsletter service, the old shop nobody thought of. That takes a few weeks.<\/p>\n<p>Then comes the step to <code>quarantine<\/code>, then to <code>reject<\/code>, and that step is where it stops, because it is the only one that can go wrong in a visible way. As long as the policy stays at <code>none<\/code>, the record exists and protects nothing.<\/p>\n<p>Which is how the most common state on the internet comes about: three records, all correct, all readable, all passing a superficial check &#8211; and a forged message in that domain&#8217;s name still arrives.<\/p>\n<h2>What five minutes of checking shows<\/h2>\n<p>All of it is public. SPF, DKIM and DMARC sit in DNS, readable by anyone for any domain, and there are four questions worth asking of any of them.<\/p>\n<p>Does an SPF record exist, does it end in <code>-all<\/code> or <code>~all<\/code>, and how close is it to the ten-lookup cap. Are DKIM keys findable, and how long are they. Does a DMARC record exist, and what does its policy say. And can the mail servers of the domain be reached at all.<\/p>\n<p>The <a href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/email-authentication-checker\/\">email authentication checker<\/a> answers all four for any domain. It counts the lookups the way a receiving server counts them, tries the common DKIM selectors, reads the DMARC policy, and says plainly which findings are facts and which are the limits of checking from outside.<\/p>\n<p>The answer worth having is short: whether a forged message in that domain&#8217;s name would be turned away &#8211; or merely noticed.<\/p>\n<div class=\"lw-faq\">\n<h2>Questions and answers<\/h2>\n<h3>Why can a forged message pass SPF and still fail DMARC?<\/h3>\n<p>Because SPF checks a different address from the one that appears in the inbox. SPF refers to the envelope sender, which is given when the message is handed over and later appears in the message as the Return-Path. The visible From line is independent of it. A forger can therefore put a domain of their own with a matching SPF record into the envelope, set someone else&#8217;s domain in the From line, and pass the SPF check.<\/p>\n<p>DMARC closes this gap with an additional condition called alignment: a passing SPF or DKIM result only counts if the checked domain matches the domain in the visible From line. For DKIM that is the domain named in the signature. A message passes DMARC as soon as one of the two checks passes and is aligned.<\/p>\n<p>For the step to reject, this implies an order. Forwarded mail usually loses its aligned SPF result, because a different server now delivers it; the DKIM signature survives forwarding as long as nobody changes the message. Mailing lists that alter the subject or append a footer, on the other hand, break the signature too. Before the policy is tightened, every system sending on behalf of the domain should therefore sign with an aligned DKIM signature. The reports from the p=none phase show where that is still missing.<\/p>\n<h3>Does a domain that sends no email at all need these records?<\/h3>\n<p>That kind of domain most of all. A domain without any outgoing mail can be locked down without risk: with an SPF record <code>v=spf1 -all<\/code> that permits no server, and a DMARC record with <code>p=reject<\/code>. Since no legitimate message exists, none can be rejected by mistake, and the weeks at p=none can be skipped.<\/p>\n<\/div>\n<div class=\"lw-quellen\">\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc7489.html\" target=\"_blank\" rel=\"noopener noreferrer\">RFC 7489: DMARC<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SPF checks which server sent the message. DKIM checks whether the message was altered. Neither of them rejects anything &#8211; that is what DMARC does, and most domains never switch it on.<\/p>\n","protected":false},"author":1,"featured_media":18804,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[137],"tags":[91099,91219,91115],"class_list":["post-13465","post","type-post","status-publish","format-standard","hentry","category-tutorials-en-it-networks","tag-server-administration","tag-tutorial","tag-web-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik<\/title>\n<meta name=\"description\" content=\"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik\" \/>\n<meta property=\"og:description\" content=\"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-06T05:35:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lukas Wojcik\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lukas Wojcik\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/\"},\"author\":{\"name\":\"Lukas Wojcik\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"headline\":\"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email\",\"datePublished\":\"2026-10-06T05:35:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/\"},\"wordCount\":1413,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png\",\"keywords\":[\"Server Administration\",\"Tutorial\",\"Web Security\"],\"articleSection\":[\"Tutorials\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/\",\"name\":\"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png\",\"datePublished\":\"2026-10-06T05:35:00+00:00\",\"description\":\"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png\",\"width\":1200,\"height\":630,\"caption\":\"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/it-networks\\\/tutorials-en-it-networks\\\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"Lukas Wojcik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"Lukas Wojcik\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik","description":"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/","og_locale":"en_US","og_type":"article","og_title":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik","og_description":"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/","og_site_name":"Lukas Wojcik - Blog","article_published_time":"2026-10-06T05:35:00+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png","type":"image\/png"}],"author":"Lukas Wojcik","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lukas Wojcik","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#article","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/"},"author":{"name":"Lukas Wojcik","@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"headline":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email","datePublished":"2026-10-06T05:35:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/"},"wordCount":1413,"commentCount":0,"publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png","keywords":["Server Administration","Tutorial","Web Security"],"articleSection":["Tutorials"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/","name":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email | Lukas Wojcik","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#primaryimage"},"image":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#primaryimage"},"thumbnailUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png","datePublished":"2026-10-06T05:35:00+00:00","description":"What SPF, DKIM and DMARC each do, why the first two cannot reject a forged email, and how to check all three for a domain in about five minutes.","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#primaryimage","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/09\/hero-13465-spf-dkim-and-dmarc-explained-simply--k.png","width":1200,"height":630,"caption":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/it-networks\/tutorials-en-it-networks\/spf-dkim-and-dmarc-explained-simply-what-each-record-checks-and-which-one\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SPF, DKIM and DMARC Explained Simply: What Each Record Checks and Which One Rejects Email"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"Lukas Wojcik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"Lukas Wojcik"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/13465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=13465"}],"version-history":[{"count":3,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/13465\/revisions"}],"predecessor-version":[{"id":21620,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/posts\/13465\/revisions\/21620"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media\/18804"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=13465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/categories?post=13465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=13465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}