Set Up Authentication

SPF Create an SPF Record

An SPF record defines which servers may send email for your domain. Here is how to set one up correctly — including the pitfalls around the lookup limit.

DKIM Set Up DKIM

DKIM cryptographically signs your outgoing email. Here is how to generate the key pair, publish the public key and verify the result.

DMARC Set Up DMARC

DMARC ties SPF and DKIM into an enforceable rule. This guide publishes the record and outlines the four phases — tightening step by step to p=reject has its own guide.

DMARC Read DMARC Reports

With p=none and a rua address you receive daily reports on who sends in your domain's name. They are the basis of every tightening step — and unreadable at first glance.

DMARC Enforce Your DMARC Policy

p=none protects nobody — it only observes. DMARC's value appears at quarantine or reject. Getting there is not hard, but it forgives no shortcut.

SPF Reduce SPF DNS Lookups

An SPF record may trigger at most ten DNS-querying mechanisms — counted across the entire chain of every include. Beyond that the record is not partly valid, it is invalid.

DKIM Rotate DKIM Keys

A DKIM change goes wrong when signing and DNS are switched in the wrong order. With a second selector it becomes a risk-free operation.

Transport Security

TLS Set Up MTA-STS & TLS-RPT

MTA-STS enforces TLS for inbound email and closes the STARTTLS downgrade gap. Set up in three steps, plus reporting.

DANE Set Up DANE

DANE binds your mail server's certificate to DNS. A sending server learns before it connects which certificate to expect — and refuses any other.

CERT Set Up the MX Certificate

For opportunistic encryption any certificate will do — nothing is verified anyway. But once MTA-STS or DANE are involved, the name in the certificate decides whether mail is delivered.

Branding & Reputation

BIMI Set Up a BIMI Logo

BIMI displays your brand logo next to your messages. It requires an enforced DMARC policy — here are all the steps.

BL Blacklist Delisting

A blacklisted IP or domain hits deliverability immediately. Here is how to find the cause and request delisting properly.

DNS Set Up Reverse DNS

Without correct reverse DNS, large providers reject connections. Three values have to agree — here is how to set them up.

BULK Bulk Sender Requirements

Since 2024 Google and Yahoo enforce binding minimum requirements for senders above roughly 5,000 messages a day to their users. What used to be advice is now a delivery condition.

LIST Set Up List-Unsubscribe

The unsubscribe button beside the sender name does not come from the link in the footer but from two headers. Miss one and the mail client shows no button — and the user reaches for “spam” instead.

IP Warm Up IP and Domain

A freshly assigned IP and a newly registered domain do not have a bad reputation — they have none at all. And with no history, large receivers do not start from a kind assumption.

The order this builds up in

These guides build on each other. Following this order means never doing the same work twice:

  1. Reverse DNS — only relevant if you run your own mail server. Without a matching PTR record many receivers reject before they ever look inside the message.
  2. Create an SPF record — defines which servers may send on behalf of your domain. The cheapest first step, because it costs nothing but a TXT record.
  3. Set up DKIM — signs every message cryptographically. Unlike SPF, DKIM survives forwarding, which makes it the sturdier of the two proofs.
  4. Set up DMARC — ties SPF and DKIM to the visible sender address and tells the receiver what to do on failure. Start at p=none with a rua address.
  5. Read the reports, then tighten — after a few weeks of aggregate reports move to p=quarantine, later to p=reject.
  6. MTA-STS and TLS-RPT — protects transport encryption against downgrade attacks. Worth doing once authentication is in place.
  7. BIMI — the logo in the inbox. It requires an enforced DMARC policy, which is why it belongs at the end rather than the start.

The order is not arbitrary: DMARC evaluates nothing but the results of SPF and DKIM. Publishing DMARC before either of them means publishing a rule that every one of your own messages fails.

Why p=reject does not come first

The most common mistake when adopting DMARC is going strict too early. In almost every organisation more systems send in the domain's name than anyone initially knows about: the newsletter tool, the ticketing system, the accounting software, an old contact form, the calendar server. Every one of them breaks under p=reject — invisibly, because rejected mail lands nowhere, not even in a spam folder.

p=none with rua changes nothing about delivery but produces exactly that list of senders. Only once nothing unfamiliar shows up there is tightening risk-free.

How long DNS changes take

Every DNS record carries a TTL — the time a foreign resolver may keep the old answer. A change therefore does not take effect everywhere at once, but at the earliest once the old record's TTL has expired. Before a migration it helps to lower the TTL a day or two in advance and raise it again afterwards.

Whether the change has landed can be checked directly: the SPF check, the DMARC check and the MX check all read the live state from DNS.

When something is already broken

If the sending IP is already on a blacklist, reconfiguration alone will not help: the cause has to be closed first — an open relay, a compromised mailbox, a form without rate limiting — otherwise the next listing follows within days, and every repeated delisting becomes harder. The delisting guide works through it step by step.

Once the groundwork is in place

The seven steps above are the mandatory part. What comes next depends on what you do:

Guide, check or error message?

Three areas with different purposes: the guides here show how to set something up. The checks explain what the report tests and how to read a result. And if your mail server returned a specific message, you will find it verbatim under error messages.

Check first, then fix

Send an email to hello@analyzemy.email. The report shows you which of these guides are relevant for your domain.

Analyze your email now