SPF vs DKIM vs DMARC

SPF vs DKIM vs DMARC is one of the most common sources of confusion in email security, and it usually comes from treating the three as competing options. They are not alternatives; they are three layers that do different jobs and are designed to work together. Understanding how SPF vs DKIM vs DMARC divide the work makes it obvious why a properly protected domain needs all three, not just one.
The short answer
SPF says which servers may send email for your domain. DKIM proves a message genuinely came from your domain and was not altered. DMARC ties the two together, decides what happens to mail that fails, and sends you reports. SPF and DKIM are the checks; DMARC is the policy and the visibility layer on top of them.
What SPF does
SPF, the Sender Policy Framework, is a DNS record listing the servers authorised to send mail for your domain. A receiving server compares the sending server against that list. Its weakness is that it checks a hidden envelope address rather than the visible from line, and it breaks when mail is forwarded. On its own, SPF cannot stop someone spoofing the address your recipients actually see. Full detail is in our guide on what SPF is.
What DKIM does
DKIM, DomainKeys Identified Mail, adds a cryptographic signature to each message using a private key, which receivers verify with a public key in your DNS. It proves authenticity and integrity, and because the signature travels with the message, it survives forwarding where SPF fails. But DKIM by itself does not tell receivers what to do when a message is unsigned or fails. See our explainer on what DKIM is.
What DMARC does
DMARC is the layer that makes SPF and DKIM meaningful. It requires alignment, meaning the authenticated domain must match the from address your recipients see, so spoofing the visible address no longer passes. It sets a policy, none, quarantine or reject, telling receivers how to handle failures, and it delivers reports showing everyone sending mail as your domain. Our guide on what DMARC is covers it in depth.
SPF vs DKIM vs DMARC at a glance
- SPF authorises sending servers. Best at listing infrastructure. Weakness: breaks on forwarding, checks a hidden address.
- DKIM signs and verifies messages. Best at proving integrity. Weakness: no enforcement rules of its own.
- DMARC enforces alignment, sets policy, and reports. Best at stopping visible-address spoofing. Weakness: it needs SPF or DKIM beneath it to work at all.
Why you need all three
Each layer covers the others’ gaps. SPF and DKIM give receivers two independent ways to authenticate your mail, and DMARC insists that at least one of them passes and aligns with the address people actually read, then blocks anything that does not. Remove any one layer and a realistic spoofing or deliverability gap opens up. This is why the answer to SPF vs DKIM vs DMARC is always all of them, in that order of setup.
Which should you set up first?
Publish SPF and DKIM first, since DMARC depends on them, then add DMARC at a monitoring policy and tighten it once your reports look clean. For a hands-on walkthrough of all three on WordPress, see our post on setting up DMARC, SPF and DKIM.
Check all three with one scan
Rather than testing each record separately, check them together. Run a security scan with EzyAudit AI and you will see SPF, DKIM and DMARC graded side by side, with plain-English guidance on what is missing or misaligned. Review the full list of checks we run. For authoritative background, the industry resource at dmarc.org explains how the three standards fit together.
Understanding SPF vs DKIM vs DMARC is the first step; deploying all three correctly is what actually protects your domain. Scan your website now to see which layers you already have.