leadhaus
← Help Centre

Deliverability

SPF, DKIM and DMARC explained in plain English

These three records are how a receiving mail server checks that an email genuinely came from the domain it claims to come from. Without them, your mail is treated as unverified, and since 2024 both Gmail and Microsoft filter unverified bulk mail heavily.

SPF: who is allowed to send

SPF is a list, published in your domain settings, of the servers permitted to send email on your behalf. When a message arrives, the receiving server checks whether it came from one of those servers.

If it did not, that is a strong signal the message is forged.

DKIM: proof the message was not tampered with

DKIM adds a cryptographic signature to every message. The receiving server checks that signature against a public key published on your domain.

A valid signature proves two things: the message genuinely came from your domain, and nobody altered it in transit.

DMARC: what to do when checks fail

DMARC ties the other two together and tells receiving servers what you want done with mail that fails: ignore the failure, quarantine it, or reject it outright.

It also enables reporting, so you can see who is sending mail claiming to be you. That is useful for spotting spoofing of your brand.

Why this became non negotiable

Gmail and Microsoft both tightened requirements for bulk senders, and authentication moved from good practice to a baseline condition of delivery. Getting this wrong is now one of the fastest routes to the spam folder.

Do you need to configure this?

Not if you are using Leadhaus outreach infrastructure, because sending happens on domains we authenticate and maintain. If you are sending from your own domain for any reason, these records need to be correct before volume goes anywhere near them.

Related

Still stuck, or want to know how this applies to your business? Ask us and a person will answer.

Get in touch