Reviewed by: QuickDMARC Security Team · Email Authentication Specialists ·

Email Authentication Guide

Complete guide to SPF, DKIM, DMARC, and BIMI for IT teams. Email authentication verifies message authenticity and prevents spoofing — required by Google and Yahoo for bulk senders since February 2024.

SPF — Sender Policy Framework

SPF (RFC 7208) publishes authorized sending IPs in a DNS TXT record. Receivers check if the connecting IP matches. Limit: 10 DNS lookups maximum.

DKIM — DomainKeys Identified Mail

DKIM (RFC 6376) adds a cryptographic signature to email headers. Receivers verify the signature against your public key in DNS.

DMARC — Policy and reporting

DMARC (RFC 7489) defines what receivers do when SPF/DKIM fail and sends aggregate reports. Policies: p=none, p=quarantine, p=reject.

BIMI — Brand indicators

BIMI displays your logo in supported inboxes. Requires DMARC at p=quarantine or p=reject plus a Verified Mark Certificate (VMC).

Recommended rollout

  1. Fix SPF and DKIM on all sending services
  2. Publish DMARC at p=none for 2–4 weeks
  3. Review reports, whitelist legitimate senders
  4. Enforce p=quarantine, then p=reject