// Engineering Log
DNS configuration for mail and website: Part 2 — Email protection (SPF, DKIM, DMARC)
Published on 2026-09-21
// Fast route
This article belongs to the topic Networking and routing.
In addition to A and MX records for mail, three other records are important: SPF, DKIM and DMARC. They confirm that messages are actually sent on behalf of your domain, protect against sender address spoofing, and help messages avoid the spam folder. Since February 2024 Gmail and Yahoo require senders who send more than 5000 messages per day to configure all three records.
SPF (Sender Policy Framework): who is allowed to send mail
What it is. SPF is a text record (
TXT) that lists the servers authorized to send mail on behalf of your domain.Why it’s needed. It protects against sender address spoofing. If a message supposedly from your domain came from a server not listed in SPF, mail providers may mark it as spam or reject it.
Example:
example.ru. IN TXT "v=spf1 mx include:_spf.yandex.net -all"v=spf1— SPF version.mxallows sending from servers in the domain’s MX records.include:_spf.yandex.netadds Yandex 360 servers if you send mail through it.-allmeans all other servers are forbidden to send. A domain can have only one SPF record, and up to ten DNS lookups are allowed when evaluating it (eachinclude,mxandais such a lookup).DKIM (DomainKeys Identified Mail): digital signature of the message
What it is. DKIM adds a digital signature to each outgoing message. The recipient verifies it using the public key published in DNS.
Why it’s needed. The signature confirms that the message was sent by an authorized server and was not altered in transit. This increases trust in messages and reduces the chance of being marked as spam.
Example:
First you need to generate a key pair. This is usually done by the mail service or server, and you publish the public key in DNS.
selector._domainkey.example.ru. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."selector— the key name, set by the mail service.p=— the public key itself. The recommended RSA key length is 2048 bits; such a key is longer than 255 characters, so in DNS it is written as several strings in quotes within a single record.DMARC (Domain-based Message Authentication, Reporting and Conformance): what to do with unverified messages
What it is. DMARC is a text record (
TXT) that tells mail providers how to handle messages that fail SPF and DKIM checks, and where to send reports about such messages.Why it’s needed. DMARC ties SPF and DKIM to the sender address visible to the recipient: a message passes validation only if the domain in SPF or DKIM matches the domain in the From field. This lets the domain owner decide how to handle forged messages.
Example:
_dmarc.example.ru. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.ru"v=DMARC1— version.p=quarantineinstructs to place messages that fail checks into spam. Other options arep=none(collect reports only) andp=reject(reject messages).rua=mailto:sets the address for aggregate reports. It’s sensible to start withp=none, verify via reports that all your legitimate mail passes checks, and only then tighten the policy.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related