InboxLoop

Email marketing and CRM guides for U.S. small businesses: list building, deliverability, automated flows, and choosing a platform.

Email Deliverability for Small Senders: SPF, DKIM and DMARC Without the Jargon

8 minutes of reading
Row of residential mailboxes in morning light

Email deliverability sounds like a technical specialism, and at large scale it is. For a small sender it comes down to a short list of habits and three DNS records. The records are not difficult, but they are unfamiliar, and the vocabulary around them is designed to be forgettable: SPF, DKIM, DMARC, alignment, policy.

This guide explains what each one does in plain language, the order to set them up, and the other things that determine whether a message reaches an inbox or the spam folder.

Read this if your marketing email lands in spam while your platform says everything is fine, or you are about to send from a new domain. You can skip it if your IT provider already manages SPF, DKIM and DMARC and sends you the reports.

Why mailbox providers care who you are

Email was designed without any built-in way to verify the sender. Anyone could put any address in the “From” line, which is why phishing and spoofing are so easy. Mailbox providers cope by checking whether a message that claims to come from your domain really does, and by tracking how people respond to mail from your domain over time.

Those two ideas, authentication and reputation, are the whole subject. Authentication proves you are who you say you are. Reputation records whether people want what you send. You can control the first completely, and influence the second through your habits.

The three records

SPF: who may send for your domain

Sender Policy Framework is a DNS record listing the servers and services authorised to send mail on behalf of your domain. When a message arrives, the receiving server checks whether it came from one of them. Think of it as a guest list at the door.

See also  Building an Email List That Stays Clean: Sign-Up Forms, Double Opt-In and Hygiene

Two practical rules. A domain should have only one SPF record, and everything that sends mail for you, including your email platform, your website’s contact form and your invoicing system, has to be included in that single record. And SPF has a limit on how many lookups it may trigger, so stacking many services into it can break it silently.

DKIM: a signature that proves the message was not altered

DomainKeys Identified Mail attaches a cryptographic signature to each message. Your platform signs outgoing mail with a private key, and you publish the matching public key in DNS. The receiving server uses the public key to confirm that the message really came from a system you authorised and that nothing changed along the way.

Most email platforms generate the DKIM record for you and show you exactly what to publish. This is usually the easiest of the three to set up and one of the most valuable.

DMARC: what to do when checks fail

Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving servers what to do with mail that claims to be from your domain but fails SPF and DKIM, and it requests reports so you can see who is sending mail as you.

It also introduces alignment: the domain shown in the visible “From” address has to match the domain that passed SPF or DKIM. Authentication that passes for a platform’s own domain but not for yours does not help you.

Three linked key shapes connecting a sender to an inbox
Three checks between you and the inbox. Each one answers a different question about who sent the message.
  • SPF. Question it answers: Is this server allowed to send for this domain?. Where it comes from: You publish it in DNS, listing your sending services.
  • DKIM. Question it answers: Was this message signed by an authorised sender and left unaltered?. Where it comes from: Your platform generates it; you publish the public key.
  • DMARC. Question it answers: What should receivers do if the checks fail, and who reports to me?. Where it comes from: You write it in DNS, usually from a short template.

Setting them up, in order

  1. Use a domain you own. You cannot authenticate mail from a free address such as a webmail account. Send marketing from your own domain, and consider a dedicated subdomain for it, so a reputation problem in marketing mail does not affect the mail your staff send day to day.
  2. List every system that sends as you. Marketing platform, CRM, helpdesk, invoicing, website forms, and any internal mail. Missing one is the most common cause of a legitimate message failing.
  3. Publish SPF including each of them in one record.
  4. Enable DKIM in each platform and publish the key records it gives you.
  5. Publish DMARC in monitoring mode first. The gentlest policy tells receivers to take no action on failures but to send you reports. Read the reports for a few weeks. They reveal forgotten systems sending as your domain, and also any spoofing.
  6. Tighten gradually. Once everything legitimate passes, move to a policy that quarantines failures, and eventually to one that rejects them. Do not skip straight to the strictest setting.
See also  Writing Subject Lines and Preheaders That Get Opened Without Tricks

One caution. These are DNS changes, and a mistake in DNS can disrupt your regular business email as well as your marketing. If DNS is managed by an IT provider or your web host, involve them, and keep a copy of the existing records before you edit anything.

Authentication is necessary, not sufficient

Passing all three checks proves you are who you say you are. It does not prove you are worth hearing from. A perfectly authenticated message from a sender whose recipients keep marking it as spam will still go to the spam folder. Reputation is built by what happens after the message arrives.

The signals that shape reputation are consistent. Spam complaints are the heaviest negative. Bounces to nonexistent addresses suggest careless list practices. Messages sent to spam-trap addresses suggest bought or scraped lists. On the positive side, opens, clicks, replies, and messages moved out of the spam folder or added to contacts all help.

Major mailbox providers have also tightened requirements for bulk senders in recent years, including expecting authentication, an easy way to unsubscribe, and low complaint rates. The exact thresholds are published by the providers and change, so check their current sender guidelines rather than relying on a figure from an article.

New domain or new platform? Warm it up

A sending domain with no history is treated cautiously, the way a new bank account is. Sending a large campaign on day one looks exactly like the behaviour of a spammer who has just registered a domain.

  • Begin with small volumes sent to your most engaged contacts, those who have recently opened, clicked or bought.
  • Increase volume gradually over a few weeks, rather than in jumps.
  • Keep content consistent and avoid sudden changes in sending pattern.
  • Watch bounce and complaint rates after each increase, and pause the ramp if either rises.
  • If you are moving from another platform, bring your history with you: send the most engaged segment first, and leave the long-dormant for later or remove them.
See also  The Five Automations Every Small Business Should Build First

Habits that protect deliverability

  • Make unsubscribing easy. A hidden unsubscribe link does not reduce unsubscribes. It converts them into spam complaints, which are much worse.
  • Use a consistent, recognisable From name and address. Changes confuse recipients and filters.
  • Send at a predictable cadence. Sudden spikes in volume draw scrutiny.
  • Keep the email balanced. Messages made of one large image with little text are treated with suspicion. Include real text and working alt text.
  • Avoid link shorteners and mismatched links. Shared shorteners are widely abused, and links whose visible text disagrees with their destination look like phishing.
  • Remove dead addresses promptly. See our guide to building a list that stays clean.

Checking where you stand

Your email platform usually shows a basic health report: bounces, complaints, and sometimes an authentication check. Beyond that, send test messages to your own accounts at several major providers and see where they land. The major providers also offer free tools that show a domain’s reputation and authentication results for the mail they receive, and they are worth setting up as soon as you send at any volume.

Nothing here guarantees inbox placement, and nobody honest will promise it. What you can do is remove every reason for a mailbox provider to distrust you: authenticate properly, send to people who asked, send what they expect, and stop quickly when they say stop.

Frequently asked questions

Do I need all three records?

In practice, yes. SPF and DKIM prove the message is yours, and DMARC tells receivers what to do when the proofs fail and sends you reports. Large mailbox providers now expect bulk senders to authenticate, so check their current published rules.

Will authenticating guarantee inbox placement?

No. It removes a reason to distrust you. Reputation, built from complaints, bounces and engagement, decides the rest.

Can I send marketing from a free webmail address?

You cannot authenticate a domain you do not own, so do not. Use your own domain, ideally a dedicated subdomain.

How long does a DNS change take?

Usually minutes to a few hours, but allow for caching. Keep a copy of the old records before you edit anything.

Written by Marcela Tran

Marcela Tran spent nine years running lifecycle email for direct-to-consumer brands and a business-services firm, which means she has built the welcome series, watched it underperform, and fixed it more times than anyone should have to. She started InboxLoop because most email advice is written by platforms that earn more when you send more. She writes for owners who send a modest number of emails and would like each one to be worth the unsubscribe risk.

All posts by this author

Keep reading