<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Affix Center Softech Services Pvt. Ltd</title>
    <description>The latest articles on DEV Community by Affix Center Softech Services Pvt. Ltd (@affix_centersoftechserv).</description>
    <link>https://dev.to/affix_centersoftechserv</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4142904%2F9035ce5d-a0a0-4133-be54-441c4218ab86.jpg</url>
      <title>DEV Community: Affix Center Softech Services Pvt. Ltd</title>
      <link>https://dev.to/affix_centersoftechserv</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/affix_centersoftechserv"/>
    <language>en</language>
    <item>
      <title>SPF, DKIM and DMARC: Email Security Setup Guide</title>
      <dc:creator>Affix Center Softech Services Pvt. Ltd</dc:creator>
      <pubDate>Fri, 25 Sep 2026 12:32:34 +0000</pubDate>
      <link>https://dev.to/affix_centersoftechserv/spf-dkim-and-dmarc-email-security-setup-guide-5aa7</link>
      <guid>https://dev.to/affix_centersoftechserv/spf-dkim-and-dmarc-email-security-setup-guide-5aa7</guid>
      <description>&lt;p&gt;&lt;em&gt;Originally published on the &lt;a href="https://affixcenter.com/blog/spf-dkim-dmarc-setup-guide" rel="noopener noreferrer"&gt;Affix Center blog&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Anyone can send an email that claims to come from your domain unless you tell the world's mail servers otherwise. Fake invoices, fake payment change requests and fake HR notices sent in a company's name are among the most common frauds Indian businesses face. This guide explains the three DNS records that stop most of this spoofing and how to put them in place without breaking your genuine email.&lt;/p&gt;

&lt;p&gt;There is a second reason to act. Since February 2024, Google and Yahoo have required bulk senders (around 5,000+ messages a day to their users) to authenticate mail with SPF, DKIM and DMARC. Microsoft introduced similar rules for high-volume senders. Even if you send far less, missing records make it more likely that your quotations and invoices land in spam.&lt;/p&gt;

&lt;h2&gt;
  
  
  What SPF, DKIM and DMARC each do
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;SPF (Sender Policy Framework):&lt;/strong&gt; a DNS record listing the servers allowed to send mail for your domain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DKIM (DomainKeys Identified Mail):&lt;/strong&gt; a digital signature added to every outgoing message, checked against a public key in your DNS.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DMARC:&lt;/strong&gt; a policy that tells receivers what to do when a message fails SPF and DKIM, and where to send reports.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SPF and DKIM prove a message is authorised. DMARC ties them to the visible "From" address and enforces the result. You need all three.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1: Inventory every system that sends your email
&lt;/h2&gt;

&lt;p&gt;List every service that sends mail using your domain: Microsoft 365 or Google Workspace, ERP/accounting (invoices), HRMS/payroll (payslips), CRM and newsletter tools, website forms, helpdesk, and scanners or on-prem apps that relay mail. The finance team's invoicing tool is the one most often forgotten.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 2: Set up SPF correctly
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;v=spf1 include:spf.yourmailprovider.com include:mail.invoicetool.com -all
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Only &lt;strong&gt;one&lt;/strong&gt; SPF record per domain.&lt;/li&gt;
&lt;li&gt;Stay within &lt;strong&gt;10 DNS lookups&lt;/strong&gt; (nested includes count).&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;-all&lt;/code&gt; rejects anything not listed; &lt;code&gt;~all&lt;/code&gt; soft-fails. Many teams start with &lt;code&gt;~all&lt;/code&gt; and rely on DMARC for enforcement.&lt;/li&gt;
&lt;li&gt;Remove includes for tools you no longer use.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Step 3: Enable DKIM signing
&lt;/h2&gt;

&lt;p&gt;In each sending service: generate a key (2048-bit where offered), publish the public key at the selector it gives you (e.g. &lt;code&gt;selector1._domainkey.yourdomain.in&lt;/code&gt;), turn signing on, and check test headers for &lt;code&gt;dkim=pass&lt;/code&gt;. Repeat for every sender.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 4: Publish DMARC and move to enforcement
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.in
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Monitor&lt;/strong&gt; with &lt;code&gt;p=none&lt;/code&gt; and read the aggregate reports.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fix&lt;/strong&gt; every legitimate sender that fails (2-4 weeks).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Quarantine&lt;/strong&gt; with &lt;code&gt;p=quarantine&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reject&lt;/strong&gt; with &lt;code&gt;p=reject&lt;/code&gt;: the goal.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For parked domains that never send mail, publish &lt;code&gt;v=spf1 -all&lt;/code&gt; and a DMARC policy of &lt;code&gt;p=reject&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 5: Test, document and maintain
&lt;/h2&gt;

&lt;p&gt;Test after every change, keep a DNS change log, add SPF/DKIM to vendor onboarding, rotate DKIM keys, and restrict DNS access with MFA on your registrar.&lt;/p&gt;

&lt;h2&gt;
  
  
  Common mistakes
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Stopping at &lt;code&gt;p=none&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Multiple SPF records added by different vendors.&lt;/li&gt;
&lt;li&gt;Forgetting that forwarding breaks SPF (so DKIM on every sender matters).&lt;/li&gt;
&lt;li&gt;Overlooking subdomains.&lt;/li&gt;
&lt;li&gt;No owner for DMARC reports.&lt;/li&gt;
&lt;li&gt;Relying on authentication alone: lookalike domains and compromised accounts need other controls.&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;Full guide with FAQs: &lt;a href="https://affixcenter.com/blog/spf-dkim-dmarc-setup-guide" rel="noopener noreferrer"&gt;SPF, DKIM and DMARC setup guide on affixcenter.com&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
    </item>
  </channel>
</rss>
