Email Authentication Guide
Complete guide to SPF, DKIM, DMARC, and BIMI for IT teams. Email authentication verifies message authenticity and prevents spoofing — required by Google and Yahoo for bulk senders since February 2024.
SPF — Sender Policy Framework
SPF (RFC 7208) publishes authorized sending IPs in a DNS TXT record. Receivers check if the connecting IP matches. Limit: 10 DNS lookups maximum.
DKIM — DomainKeys Identified Mail
DKIM (RFC 6376) adds a cryptographic signature to email headers. Receivers verify the signature against your public key in DNS.
DMARC — Policy and reporting
DMARC (RFC 7489) defines what receivers do when SPF/DKIM fail and sends aggregate reports. Policies: p=none, p=quarantine, p=reject.
BIMI — Brand indicators
BIMI displays your logo in supported inboxes. Requires DMARC at p=quarantine or p=reject plus a Verified Mark Certificate (VMC).
Recommended rollout
- Fix SPF and DKIM on all sending services
- Publish DMARC at p=none for 2–4 weeks
- Review reports, whitelist legitimate senders
- Enforce p=quarantine, then p=reject