Set up email authentication in this order
SPF, DKIM and DMARC each answer a different question about a message. DMARC depends on the other two, so the order matters.
| Step | Record | What it proves | Tool |
|---|---|---|---|
| 1 | SPF | The sending server is allowed to send for your domain | SPF record generator |
| 2 | DKIM | The owner of the domain signed the message | DKIM generator |
| 3 | DMARC | SPF or DKIM passed and lines up with the From domain | DMARC record generator |
| 4 | Clean list | The addresses you send to exist | Email verifier |
Google says to run SPF and DKIM for at least 48 hours before you turn DMARC on, and to start DMARC at p=none.
Skip the setup with TrueEmailer
In TrueEmailer, SPF, DKIM and DMARC are configured at setup, and mail leaves from pre-warmed SMTP infrastructure. See deliverability and warmup.
Passing authentication proves a message is allowed to use your domain. It does not set your reputation. Complaint rates, list quality and message content still decide where mail lands.
Free tools FAQ
Are these tools free?
+
Yes. The DKIM, SPF and DMARC generators are free with no limit and no signup. The email verifier gives guests 5 free checks a day.
Which record should I set up first?
+
Set up SPF and DKIM first, then DMARC. Google says a message passes DMARC when it passes SPF or DKIM with alignment, and says to run SPF and DKIM for at least 48 hours before you turn DMARC on.
Do I need SPF, DKIM and DMARC?
+
Google requires SPF or DKIM from everyone who sends to personal Gmail accounts, and all three of SPF, DKIM and DMARC from senders above 5,000 messages a day.
Does TrueEmailer store what I enter?
+
The DKIM generator creates keys in your browser, so the private key is never sent to TrueEmailer. The SPF and DMARC generators build the record in your browser. The record checks query public DNS.