Email deliverability guide

SPF DKIM DMARC Checklist

A practical authentication checklist for SPF authorization, DKIM signatures and DMARC alignment.

Already have an Inbox Warmup account? Go directly to Dashboard

A practical authentication checklist for SPF authorization, DKIM signatures and DMARC alignment.

Key takeaway
SPF, DKIM and DMARC solve different parts of email authentication. Passing one does not replace the others, and syntactically valid records may still fail alignment.

Why spf dkim dmarc checklist matters

SPF, DKIM and DMARC solve different parts of email authentication. Passing one does not replace the others, and syntactically valid records may still fail alignment.

Good sending performance comes from several systems working together: a legitimate sender identity, correctly aligned authentication, a reliable connection, controlled volume, relevant recipients and fast action when warning signs appear. This guide is designed to help you review those areas in a logical order instead of changing settings randomly.

Step-by-step process

  1. Confirm there is only one SPF TXT record — complete this check and record the result before moving to the next stage.
  2. Authorize every legitimate sending source — complete this check and record the result before moving to the next stage.
  3. Keep SPF lookup count within protocol limits — complete this check and record the result before moving to the next stage.
  4. Enable DKIM signing with the correct selector — complete this check and record the result before moving to the next stage.
  5. Verify the public DKIM key is reachable — complete this check and record the result before moving to the next stage.
  6. Publish a DMARC record at _dmarc — complete this check and record the result before moving to the next stage.
  7. Confirm SPF or DKIM aligns with the From domain — complete this check and record the result before moving to the next stage.
  8. Monitor reports before increasing enforcement — complete this check and record the result before moving to the next stage.

Before you begin

Make sure you control the domain, can edit DNS, can access the sending mailbox or SMTP account, and know which service actually sends the message. Keep a copy of current records before changing anything.

Before you scale

Confirm that authentication passes on real messages, connection errors are resolved, bounces are understood and sending volume is stable. Scale in measured steps rather than moving directly to a provider maximum.

  1. Identify one measurable problem.
  2. Change the smallest relevant setting or behaviour.
  3. Allow enough time for DNS or provider data to update.
  4. Retest using the same method.
  5. Keep the change only when the evidence improves.

Use a controlled improvement cycle

Record the date of each test, the domain or mailbox tested, the sending provider and the exact result. This creates a useful baseline for future troubleshooting. When performance changes, compare the new data with the last known-good configuration instead of replacing several records or providers at once.

A single passing check should not be treated as final proof that the entire sending setup is healthy. Authentication results, SMTP responses and reputation indicators should be reviewed together and compared over time. For example, SPF may pass while DKIM is missing, or an SMTP connection may succeed while the chosen From address is not authorized to relay.

How to interpret the results

What to monitor after setup

Continue reviewing the following signals after the initial configuration. A correct setup can still deteriorate when passwords change, DNS is edited, contact quality drops or campaign volume increases too quickly.

  • SPF, DKIM and DMARC results on real sent messages
  • SMTP rejection, deferral and authentication responses
  • Hard bounces, repeated soft bounces and invalid recipients
  • Complaint and unsubscribe trends
  • Changes in hourly and daily sending volume
  • Provider-specific feedback and reputation data where available
  • Meaningful replies and recipient engagement, not only open tracking

Common mistakes to avoid

  • Creating separate SPF records for each provider
  • Copying DKIM values from another domain
  • Publishing DMARC at the root instead of _dmarc
  • Using p=reject before all legitimate sources are aligned
  • Assuming a green syntax check proves real messages pass
Important limitation: Inbox Warmup can help with controlled warmup, authentication checks and infrastructure readiness. No software can guarantee inbox placement, replies or campaign revenue. Results also depend on recipient quality, content, complaints, sending history and mailbox-provider decisions.

Useful tools for this guide

Related Inbox Warmup solutions

Frequently asked questions

Do I need all three?

For modern business sending, using SPF, DKIM and DMARC together provides stronger authentication and reporting.

Can SPF pass while DMARC fails?

Yes. SPF may authenticate a return-path domain that does not align with the visible From domain.

How do I verify DKIM?

Send a controlled message and inspect the DKIM signature and authentication results, not only the DNS record.

Recommended next step

Use the checks above to document the current state of your domain and mailbox. Fix authentication and connection errors first, then begin controlled warmup and monitor real results before increasing campaign volume.

Next step

Turn this into a controlled warmup plan.

Connect your infrastructure, verify authentication, warm up gradually and understand your reputation before scaling.