Related articles

SPF, DKIM and DMARC: email protection explained

Sep 20, 2026 | News, Security

By Herbert Röblreiter

SPF, DKIM and DMARC are three distinct tools for more trustworthy email communication. They complement strong passwords and good security practices, reducing the risk of unauthorised systems sending messages in your domain’s name.

SPF: which systems may send?

An SPF record identifies the mail servers authorised to send for a domain. This matters particularly when Microsoft 365, Google Workspace, a newsletter platform, a ticketing system or your own mail server are used together. All authorised sending channels need to be recorded correctly.

DKIM: authenticate messages with a cryptographic signature

DKIM adds a signature to outgoing emails. Receiving servers can check that a message was sent through an authorised system and has not been altered in transit. Multiple DKIM keys are normal when several sending platforms are in use.

DMARC: define how to handle failures

DMARC connects the checks and defines a policy. A common approach is to start with monitoring, review the reports and then tighten the policy gradually. This helps avoid legitimate messages being rejected unintentionally.

ToolPurpose
SPFDefine authorised sending sources
DKIMCryptographically sign the message’s origin and integrity
DMARCEvaluate checks and control policies

What is often overlooked

A domain often has more sending channels than expected: online forms, ERP systems, scanners, monitoring, accounting software or external providers. The configuration therefore needs ongoing attention. Changes to platforms and new senders belong in a documented process.

DAXS helps identify existing sending channels, configure DNS, monitor results and develop SPF, DKIM and DMARC together. This is a service component that can be agreed separately; it is not automatically included in every support arrangement.