<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Abdul Mateen</title>
    <description>The latest articles on DEV Community by Abdul Mateen (@maddy54515).</description>
    <link>https://dev.to/maddy54515</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4164729%2F58f1a9d2-f5a4-433c-b84f-5e4b55da4319.jpg</url>
      <title>DEV Community: Abdul Mateen</title>
      <link>https://dev.to/maddy54515</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/maddy54515"/>
    <language>en</language>
    <item>
      <title>SPF DKIM DMARC Setup for Small Business: 2026 Guide</title>
      <dc:creator>Abdul Mateen</dc:creator>
      <pubDate>Mon, 05 Oct 2026 19:13:36 +0000</pubDate>
      <link>https://dev.to/maddy54515/spf-dkim-dmarc-setup-for-small-business-2026-guide-3l0n</link>
      <guid>https://dev.to/maddy54515/spf-dkim-dmarc-setup-for-small-business-2026-guide-3l0n</guid>
      <description>&lt;p&gt;Your staff email may come from Microsoft 365 or Google Workspace. Your invoices may come from accounting software. Your website may send contact-form confirmations. Your CRM or newsletter tool may send from the same business domain.&lt;/p&gt;

&lt;p&gt;That is why a safe &lt;strong&gt;SPF DKIM DMARC setup&lt;/strong&gt; starts with a sender list, not with copying three DNS records from a tutorial.&lt;/p&gt;

&lt;p&gt;This guide shows you how to set up email authentication for a small business, test every real sending system, and avoid common mistakes that can break legitimate mail. It also explains an important 2026 change: the current DMARC standard is now RFC 9989, not the older RFC 7489.&lt;/p&gt;

&lt;p&gt;This is not just theory. In early October 2026, attackers were actively exploiting a critical FortiMail flaw (CVE-2026-104286) with no login required. Email systems are live targets, which is why getting authentication right matters.&lt;/p&gt;

&lt;h2&gt;
  
  
  SPF DKIM DMARC Setup: The Safe Order
&lt;/h2&gt;

&lt;p&gt;Use this order:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;List every service that sends email using your domain.&lt;/li&gt;
&lt;li&gt;Save your current DNS records before changing anything.&lt;/li&gt;
&lt;li&gt;Build one valid SPF policy for each sending domain.&lt;/li&gt;
&lt;li&gt;Enable DKIM in each service that supports it.&lt;/li&gt;
&lt;li&gt;Send real test messages and confirm SPF/DKIM results.&lt;/li&gt;
&lt;li&gt;Understand DMARC alignment before publishing DMARC.&lt;/li&gt;
&lt;li&gt;Start with monitoring where that fits your active business domain and risk.&lt;/li&gt;
&lt;li&gt;Verify each real message flow, not just staff email.&lt;/li&gt;
&lt;li&gt;Review DMARC reports before changing enforcement.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Do not assume Microsoft 365 or Google Workspace is your only sender. A forgotten invoicing tool, website form, CRM, scanner, or marketing platform can be the reason legitimate mail fails after a DNS change.&lt;/p&gt;

&lt;h2&gt;
  
  
  SPF vs. DKIM vs. DMARC in Plain English
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Control&lt;/th&gt;
&lt;th&gt;What it checks&lt;/th&gt;
&lt;th&gt;What you publish in DNS&lt;/th&gt;
&lt;th&gt;What it does not prove&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;SPF&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Whether the sending server is allowed for the envelope-sender domain&lt;/td&gt;
&lt;td&gt;One SPF TXT policy for that domain&lt;/td&gt;
&lt;td&gt;That the visible From address is aligned&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DKIM&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Whether a message has a valid cryptographic signature tied to a domain&lt;/td&gt;
&lt;td&gt;A public key or provider CNAME&lt;/td&gt;
&lt;td&gt;That your service is actually signing mail with your business domain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DMARC&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Whether SPF or DKIM passes &lt;strong&gt;and aligns&lt;/strong&gt; with the visible From domain&lt;/td&gt;
&lt;td&gt;A DMARC TXT policy and optional reporting addresses&lt;/td&gt;
&lt;td&gt;That the message itself is safe or trustworthy&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;A message can pass SPF and DKIM and still fail DMARC if the authenticated domains do not align with the domain the recipient sees in the From address.&lt;/p&gt;

&lt;h2&gt;
  
  
  Before You Touch DNS: List Every System That Sends Email
&lt;/h2&gt;

&lt;p&gt;Start with an inventory.&lt;/p&gt;

&lt;p&gt;Common business senders include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Microsoft 365 or Google Workspace&lt;/li&gt;
&lt;li&gt;accounting and invoicing software&lt;/li&gt;
&lt;li&gt;CRM&lt;/li&gt;
&lt;li&gt;newsletter or marketing platforms&lt;/li&gt;
&lt;li&gt;help-desk software&lt;/li&gt;
&lt;li&gt;payroll systems&lt;/li&gt;
&lt;li&gt;website contact forms&lt;/li&gt;
&lt;li&gt;WordPress notifications&lt;/li&gt;
&lt;li&gt;booking systems&lt;/li&gt;
&lt;li&gt;e-commerce platforms&lt;/li&gt;
&lt;li&gt;scanners and multifunction printers&lt;/li&gt;
&lt;li&gt;monitoring and alert services&lt;/li&gt;
&lt;li&gt;customer portals&lt;/li&gt;
&lt;li&gt;transactional email providers&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Do not add a service to SPF only because a scanner says it is missing. First confirm that the service actually sends mail using your domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  Sender inventory worksheet
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Sending System&lt;/th&gt;
&lt;th&gt;Example Message&lt;/th&gt;
&lt;th&gt;Visible From Domain&lt;/th&gt;
&lt;th&gt;Provider&lt;/th&gt;
&lt;th&gt;Owner&lt;/th&gt;
&lt;th&gt;Uses Your Domain?&lt;/th&gt;
&lt;th&gt;SPF Path Known?&lt;/th&gt;
&lt;th&gt;DKIM Available?&lt;/th&gt;
&lt;th&gt;Test Sent?&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Employee email&lt;/td&gt;
&lt;td&gt;Staff email&lt;/td&gt;
&lt;td&gt;example.com&lt;/td&gt;
&lt;td&gt;Microsoft/Google&lt;/td&gt;
&lt;td&gt;IT/Owner&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Accounting&lt;/td&gt;
&lt;td&gt;Invoice&lt;/td&gt;
&lt;td&gt;example.com&lt;/td&gt;
&lt;td&gt;Vendor&lt;/td&gt;
&lt;td&gt;Finance&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Website&lt;/td&gt;
&lt;td&gt;Contact-form confirmation&lt;/td&gt;
&lt;td&gt;example.com&lt;/td&gt;
&lt;td&gt;Web host/SMTP provider&lt;/td&gt;
&lt;td&gt;Website owner&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;strong&gt;Do not store passwords, API keys, DKIM private keys, recovery codes, or other secrets in this worksheet.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1: Save Your Current DNS Configuration
&lt;/h2&gt;

&lt;p&gt;Before changing DNS, save what is already there.&lt;/p&gt;

&lt;p&gt;Record:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;current SPF TXT record;&lt;/li&gt;
&lt;li&gt;current DKIM selectors and records;&lt;/li&gt;
&lt;li&gt;current DMARC TXT record;&lt;/li&gt;
&lt;li&gt;TTL values;&lt;/li&gt;
&lt;li&gt;DNS provider;&lt;/li&gt;
&lt;li&gt;current email provider;&lt;/li&gt;
&lt;li&gt;date and time of the snapshot.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This gives you a reference point if something stops working.&lt;/p&gt;

&lt;h3&gt;
  
  
  DNS change log
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Record&lt;/th&gt;
&lt;th&gt;Previous Value&lt;/th&gt;
&lt;th&gt;New Value&lt;/th&gt;
&lt;th&gt;Reason&lt;/th&gt;
&lt;th&gt;Changed By&lt;/th&gt;
&lt;th&gt;Verified?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Do not delete an existing record just because a setup guide shows a different value. First work out what the current record is doing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 2: Set Up SPF Without Creating Multiple SPF Records
&lt;/h2&gt;

&lt;p&gt;SPF is checked against the domain used in the SMTP envelope sender, often called the &lt;strong&gt;MAIL FROM&lt;/strong&gt; or &lt;strong&gt;Return-Path&lt;/strong&gt; domain.&lt;/p&gt;

&lt;p&gt;If you use SPF for a domain, publish &lt;strong&gt;one SPF policy&lt;/strong&gt;, not one SPF record for every service.&lt;/p&gt;

&lt;p&gt;Multiple SPF records for the same domain cause an SPF permanent error (&lt;code&gt;permerror&lt;/code&gt;) under the SPF standard.&lt;/p&gt;

&lt;h3&gt;
  
  
  Google Workspace example
&lt;/h3&gt;

&lt;p&gt;If Google Workspace is the &lt;strong&gt;only&lt;/strong&gt; system sending mail for the domain, Google currently documents:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;v=spf1 include:_spf.google.com ~all
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Do not copy that record unchanged if other services also send mail for the same domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  Microsoft 365 example
&lt;/h3&gt;

&lt;p&gt;For a standard commercial Microsoft 365 domain where Microsoft 365 is the only sender, Microsoft currently documents:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;v=spf1 include:spf.protection.outlook.com -all
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Microsoft uses different values for some government and regional cloud environments, so use the record shown in the official documentation for your tenant.&lt;/p&gt;

&lt;h3&gt;
  
  
  If several services send mail
&lt;/h3&gt;

&lt;p&gt;The answer is usually &lt;strong&gt;not&lt;/strong&gt; to publish a second SPF record.&lt;/p&gt;

&lt;p&gt;You need to build one policy that represents the authorized sources for that specific envelope-sender domain. Some services use their own bounce or Return-Path domain, so they may not need to appear in the SPF record for your main domain at all.&lt;/p&gt;

&lt;p&gt;This is why sender inventory comes first.&lt;/p&gt;

&lt;h3&gt;
  
  
  The SPF 10-DNS-lookup limit
&lt;/h3&gt;

&lt;p&gt;RFC 7208 limits SPF evaluation to &lt;strong&gt;10 DNS-query-causing terms&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;These include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;include&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;a&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;mx&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ptr&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;exists&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;redirect&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The count can include lookups triggered through nested &lt;code&gt;include&lt;/code&gt; or &lt;code&gt;redirect&lt;/code&gt; processing. If the limit is exceeded during evaluation, SPF returns &lt;code&gt;permerror&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;That does not mean every recipient will handle the message in exactly the same way, but it means SPF is no longer producing a normal pass/fail result for that evaluation.&lt;/p&gt;

&lt;p&gt;Do not keep adding SaaS &lt;code&gt;include&lt;/code&gt; values without checking the total lookup path.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should you flatten SPF?
&lt;/h3&gt;

&lt;p&gt;Do not treat SPF flattening as an automatic fix.&lt;/p&gt;

&lt;p&gt;Manually replacing provider includes with IP addresses can create maintenance problems because the provider may change its sending infrastructure later.&lt;/p&gt;

&lt;p&gt;If your SPF design is approaching the lookup limit, first ask:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Does every listed service still send mail?&lt;/li&gt;
&lt;li&gt;Can a third-party service use its own aligned subdomain?&lt;/li&gt;
&lt;li&gt;Can DKIM alignment handle that service instead?&lt;/li&gt;
&lt;li&gt;Can unused includes be removed?&lt;/li&gt;
&lt;li&gt;Does the provider offer a supported design that reduces lookups?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Fix the architecture before adding more complexity.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3: Enable DKIM — Then Prove It Is Actually Signing
&lt;/h2&gt;

&lt;p&gt;A DKIM record in DNS does not prove your mail is being signed correctly.&lt;/p&gt;

&lt;p&gt;There are two parts:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Publish the public key, or provider CNAME, in DNS.&lt;/li&gt;
&lt;li&gt;Enable DKIM signing in the sending service.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Then send a real message and check the headers.&lt;/p&gt;

&lt;p&gt;Look for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;DKIM=pass&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;the DKIM signing domain (&lt;code&gt;d=&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;the selector (&lt;code&gt;s=&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The &lt;code&gt;d=&lt;/code&gt; domain matters for DMARC alignment.&lt;/p&gt;

&lt;h3&gt;
  
  
  Microsoft 365
&lt;/h3&gt;

&lt;p&gt;Microsoft 365 automatically DKIM-signs mail sent from its initial &lt;code&gt;onmicrosoft.com&lt;/code&gt; domain. For a &lt;strong&gt;custom domain&lt;/strong&gt;, Microsoft says you must configure DKIM signing for that custom domain if you want the custom domain to be used for the DKIM signature.&lt;/p&gt;

&lt;p&gt;Current Microsoft 365 DKIM setup uses two CNAME selectors. Microsoft changed the CNAME target format for newer custom domains in 2025, so do not build the target values yourself.&lt;/p&gt;

&lt;p&gt;Get the exact values from:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Microsoft Defender portal → Email &amp;amp; collaboration → Policies &amp;amp; rules → Threat policies → Email authentication settings → DKIM&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Microsoft also exposes the selector values through Exchange Online PowerShell.&lt;/p&gt;

&lt;p&gt;After the CNAME records are detected, enable signing and send a test message. Confirm the custom domain appears in the DKIM &lt;code&gt;d=&lt;/code&gt; value.&lt;/p&gt;

&lt;p&gt;Official guide:&lt;br&gt;
&lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;
  
  
  Google Workspace
&lt;/h3&gt;

&lt;p&gt;Google Workspace uses a different process:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open &lt;strong&gt;Admin console → Apps → Google Workspace → Gmail → Authenticate email&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Generate a DKIM key if one has not already been provisioned.&lt;/li&gt;
&lt;li&gt;Publish the TXT record Google gives you.&lt;/li&gt;
&lt;li&gt;Return to the Admin console.&lt;/li&gt;
&lt;li&gt;Start authentication.&lt;/li&gt;
&lt;li&gt;Send a real test message and verify the DKIM result.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Google notes that after Gmail is first turned on for an organization, you may need to wait &lt;strong&gt;24–72 hours before a DKIM key can be generated&lt;/strong&gt; in the Admin console. That is not the same thing as saying every DKIM DNS change takes 24–72 hours.&lt;/p&gt;

&lt;p&gt;For DNS changes themselves, wait according to your DNS TTL and Google's verification message if the key is not found yet.&lt;/p&gt;

&lt;p&gt;Official guide:&lt;br&gt;
&lt;a href="https://support.google.com/a/answer/174124" rel="noopener noreferrer"&gt;https://support.google.com/a/answer/174124&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Step 4: Understand DMARC Alignment Before Publishing DMARC
&lt;/h2&gt;

&lt;p&gt;DMARC does not ask only:&lt;/p&gt;

&lt;p&gt;“Did SPF pass?”&lt;br&gt;
or&lt;br&gt;
“Did DKIM pass?”&lt;/p&gt;

&lt;p&gt;It asks whether at least one passing method is also &lt;strong&gt;aligned&lt;/strong&gt; with the domain in the visible From address.&lt;/p&gt;
&lt;h3&gt;
  
  
  Simple example
&lt;/h3&gt;

&lt;p&gt;A customer sees:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;From: billing@example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But the third-party invoicing service authenticates:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;SPF domain: vendor-mail.example.net
DKIM d=: vendor-mail.example.net
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;SPF can pass. DKIM can pass.&lt;/p&gt;

&lt;p&gt;DMARC can still fail because neither authenticated domain aligns with &lt;code&gt;example.com&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  What alignment means
&lt;/h3&gt;

&lt;p&gt;With DMARC's default &lt;strong&gt;relaxed alignment&lt;/strong&gt;, the authenticated domain and visible From domain can be different subdomains as long as they share the same Organizational Domain.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;From: billing@example.com
DKIM d=mail.example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;can align in relaxed mode.&lt;/p&gt;

&lt;p&gt;With &lt;strong&gt;strict alignment&lt;/strong&gt;, the domains must match exactly.&lt;/p&gt;

&lt;p&gt;For most small businesses, you do not need to change alignment modes just to complete a normal setup. You do need to understand why a third-party provider passing SPF or DKIM on its own unrelated domain may still fail DMARC for your business domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  How third-party services usually solve alignment
&lt;/h3&gt;

&lt;p&gt;Look for settings such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;domain authentication;&lt;/li&gt;
&lt;li&gt;custom DKIM;&lt;/li&gt;
&lt;li&gt;custom signing domain;&lt;/li&gt;
&lt;li&gt;custom Return-Path;&lt;/li&gt;
&lt;li&gt;custom bounce domain.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Do not assume adding the provider to SPF will always fix DMARC. If the provider uses its own Return-Path domain, SPF may still not align with your visible From domain. Custom DKIM is often the cleaner path.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 5: Publish DMARC Monitoring Carefully
&lt;/h2&gt;

&lt;p&gt;For an active business domain where you are still discovering senders, a monitoring policy can be a practical starting point.&lt;/p&gt;

&lt;p&gt;An illustrative record is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Do not paste this unchanged.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Replace the reporting address with a real mailbox or DMARC reporting service that you control.&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;rua&lt;/code&gt; tag asks participating receivers to send aggregate DMARC reports. RFC 9990 is the current aggregate-reporting specification. These reports are machine-readable XML, so many small businesses use a reporting service or parser rather than reading raw XML files by hand.&lt;/p&gt;

&lt;p&gt;If the reporting address is on a different domain, external-reporting authorization may be required. Follow your reporting provider's current setup instructions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is &lt;code&gt;p=none&lt;/code&gt; always the right starting policy?
&lt;/h3&gt;

&lt;p&gt;No universal policy fits every domain.&lt;/p&gt;

&lt;p&gt;For an established, general-purpose business domain with several sending systems and incomplete visibility, &lt;code&gt;p=none&lt;/code&gt; is often a low-risk way to collect evidence before enforcement.&lt;/p&gt;

&lt;p&gt;A parked domain that should never send mail is a different case. A tightly controlled dedicated sending domain can also have a different path.&lt;/p&gt;

&lt;p&gt;The right policy depends on the purpose of the domain and its legitimate mail flows.&lt;/p&gt;

&lt;p&gt;Once monitoring is working, use BizRiskGuide's guide:&lt;br&gt;
&lt;a href="https://bizriskguide.com/dmarc-p-none-next-steps/" rel="noopener noreferrer"&gt;DMARC p=none: What Should Your Small Business Do Next?&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;That article covers report review and the decision about what policy should come next.&lt;/p&gt;
&lt;h2&gt;
  
  
  A 2026 DMARC Change You Should Know About
&lt;/h2&gt;

&lt;p&gt;In May 2026, the IETF published &lt;strong&gt;RFC 9989&lt;/strong&gt;, the current DMARC specification. It obsoletes RFC 7489 and RFC 9091.&lt;/p&gt;

&lt;p&gt;Two changes matter when you read older setup guides.&lt;/p&gt;
&lt;h3&gt;
  
  
  The &lt;code&gt;pct&lt;/code&gt; tag was removed
&lt;/h3&gt;

&lt;p&gt;Older guides often show records such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;pct=10
pct=25
pct=50
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;RFC 9989 removed the &lt;code&gt;pct&lt;/code&gt; tag because real-world implementation was inconsistent.&lt;/p&gt;

&lt;p&gt;The new standard adds a &lt;code&gt;t&lt;/code&gt; testing tag, but it does &lt;strong&gt;not&lt;/strong&gt; provide percentage-based rollout. &lt;code&gt;t=y&lt;/code&gt; asks receivers not to apply the stated policy fully and, for a failing message, effectively requests treatment one level below the published policy.&lt;/p&gt;

&lt;p&gt;For a small-business setup, you do not need to add &lt;code&gt;t=y&lt;/code&gt; just because it exists. Receiver support and provider guidance may vary, so use it only when you understand why you need it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do not assume every domain should end at &lt;code&gt;p=reject&lt;/code&gt;
&lt;/h3&gt;

&lt;p&gt;RFC 9989 explicitly says that domains used for &lt;strong&gt;general-purpose email should not automatically deploy &lt;code&gt;p=reject&lt;/code&gt;&lt;/strong&gt;, because indirect mail flows such as mailing lists can create interoperability problems.&lt;/p&gt;

&lt;p&gt;This is an important change in how the standard explains deployment.&lt;/p&gt;

&lt;p&gt;Do not follow a rigid:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;p=none → p=quarantine → p=reject
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;ladder without looking at your real mail.&lt;/p&gt;

&lt;h3&gt;
  
  
  Provider documentation may still show older examples
&lt;/h3&gt;

&lt;p&gt;At the time of this 2026 review, Google's Workspace DMARC rollout page still shows &lt;code&gt;pct=&lt;/code&gt; examples even though RFC 9989 has removed that tag from the current standard.&lt;/p&gt;

&lt;p&gt;That is a documentation transition issue. Do not add &lt;code&gt;pct=&lt;/code&gt; merely because an older or not-yet-updated provider article still shows it.&lt;/p&gt;

&lt;p&gt;Current RFC:&lt;br&gt;
&lt;a href="https://www.rfc-editor.org/rfc/rfc9989.html" rel="noopener noreferrer"&gt;https://www.rfc-editor.org/rfc/rfc9989.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Current aggregate reporting RFC:&lt;br&gt;
&lt;a href="https://www.rfc-editor.org/rfc/rfc9990.html" rel="noopener noreferrer"&gt;https://www.rfc-editor.org/rfc/rfc9990.html&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Microsoft 365 Setup Path
&lt;/h2&gt;

&lt;p&gt;Use this as a checklist, not as a substitute for Microsoft's live DNS values.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Confirm the custom domain is verified in Microsoft 365.&lt;/li&gt;
&lt;li&gt;Review the existing SPF record.&lt;/li&gt;
&lt;li&gt;If Microsoft 365 sends mail for that domain, make sure Microsoft 365 is represented in the one SPF policy.&lt;/li&gt;
&lt;li&gt;Open Microsoft Defender's &lt;strong&gt;Email authentication settings&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the custom domain under DKIM.&lt;/li&gt;
&lt;li&gt;Copy the exact two CNAME values Microsoft gives you.&lt;/li&gt;
&lt;li&gt;Publish them in DNS.&lt;/li&gt;
&lt;li&gt;Enable DKIM for the custom domain after Microsoft detects the records.&lt;/li&gt;
&lt;li&gt;Send a real message and verify DKIM.&lt;/li&gt;
&lt;li&gt;Publish DMARC only after you understand the real senders and alignment.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Microsoft's current email-authentication overview recommends SPF, DKIM, and DMARC working together for custom domains.&lt;/p&gt;

&lt;p&gt;Official references:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SPF: &lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;DKIM: &lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;DMARC: &lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  Google Workspace Setup Path
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;List all services that send mail for the domain.&lt;/li&gt;
&lt;li&gt;Review the existing SPF policy.&lt;/li&gt;
&lt;li&gt;If Google Workspace sends mail, make sure Google's authorized source is represented in the one SPF policy.&lt;/li&gt;
&lt;li&gt;Open &lt;strong&gt;Admin console → Apps → Google Workspace → Gmail → Authenticate email&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Generate the DKIM key when available.&lt;/li&gt;
&lt;li&gt;Publish the TXT record Google gives you.&lt;/li&gt;
&lt;li&gt;Start authentication in the Admin console.&lt;/li&gt;
&lt;li&gt;Send a real message and confirm DKIM passes.&lt;/li&gt;
&lt;li&gt;Publish DMARC monitoring when appropriate.&lt;/li&gt;
&lt;li&gt;Test every other sender separately.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Google's SPF guide explicitly tells administrators to identify &lt;strong&gt;all&lt;/strong&gt; senders first, including web servers, contact forms, outbound gateways, and third-party providers.&lt;/p&gt;

&lt;p&gt;Official references:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;SPF: &lt;a href="https://support.google.com/a/answer/33786" rel="noopener noreferrer"&gt;https://support.google.com/a/answer/33786&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;DKIM: &lt;a href="https://support.google.com/a/answer/174124" rel="noopener noreferrer"&gt;https://support.google.com/a/answer/174124&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;DMARC: &lt;a href="https://support.google.com/a/answer/2466580" rel="noopener noreferrer"&gt;https://support.google.com/a/answer/2466580&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  What About CRM, Invoicing, Marketing, and SaaS Email?
&lt;/h2&gt;

&lt;p&gt;Third-party services are where small-business email authentication often gets complicated.&lt;/p&gt;

&lt;p&gt;For each provider:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open its &lt;strong&gt;domain authentication&lt;/strong&gt; or &lt;strong&gt;sender authentication&lt;/strong&gt; settings.&lt;/li&gt;
&lt;li&gt;Use the DNS values generated for your account.&lt;/li&gt;
&lt;li&gt;Enable custom DKIM if supported.&lt;/li&gt;
&lt;li&gt;Configure a custom Return-Path or bounce domain if the provider supports it and you need SPF alignment.&lt;/li&gt;
&lt;li&gt;Send a real message.&lt;/li&gt;
&lt;li&gt;Inspect the final authentication results.&lt;/li&gt;
&lt;li&gt;Record the result in your worksheet.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Do not copy Mailchimp, Brevo, Salesforce, HubSpot, or another vendor's record from an unrelated blog post. Use the current values shown inside your own account or the provider's current official documentation.&lt;/p&gt;
&lt;h2&gt;
  
  
  What About WordPress and Website Contact Forms?
&lt;/h2&gt;

&lt;p&gt;A website form can be one of the senders you forget.&lt;/p&gt;

&lt;p&gt;First find out how the site actually sends mail:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;local web-server/PHP mail;&lt;/li&gt;
&lt;li&gt;authenticated SMTP;&lt;/li&gt;
&lt;li&gt;Microsoft 365;&lt;/li&gt;
&lt;li&gt;Google Workspace;&lt;/li&gt;
&lt;li&gt;a transactional mail provider;&lt;/li&gt;
&lt;li&gt;a WordPress mail plugin connected to one of those services.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For reliable authentication, use a supported mail route that can authenticate your domain.&lt;/p&gt;

&lt;p&gt;Where the form lets you choose headers, a safer design is usually:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;From: website@example.com
Reply-To: visitor@example.net
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;rather than pretending the message was sent directly from the visitor's external address.&lt;/p&gt;

&lt;p&gt;Then test both:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the internal notification your staff receives; and&lt;/li&gt;
&lt;li&gt;the confirmation message the customer receives, if your form sends one.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Do not assume a form works correctly just because the message arrived in your own inbox once.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 6: Test Every Real Sending System
&lt;/h2&gt;

&lt;p&gt;One successful Microsoft 365 or Google Workspace message does not prove your invoices, newsletters, website email, and CRM notifications are authenticated.&lt;/p&gt;

&lt;p&gt;Test each message type.&lt;/p&gt;

&lt;h3&gt;
  
  
  Verification matrix
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Sending System&lt;/th&gt;
&lt;th&gt;Visible From&lt;/th&gt;
&lt;th&gt;Return-Path / SPF Domain&lt;/th&gt;
&lt;th&gt;DKIM &lt;code&gt;d=&lt;/code&gt; Domain&lt;/th&gt;
&lt;th&gt;SPF Result&lt;/th&gt;
&lt;th&gt;DKIM Result&lt;/th&gt;
&lt;th&gt;DMARC Result&lt;/th&gt;
&lt;th&gt;Alignment Confirmed?&lt;/th&gt;
&lt;th&gt;Test Date&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Staff email&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Invoice&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Website form&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CRM&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Newsletter&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For every important sender:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Send a real message to an inbox you control.&lt;/li&gt;
&lt;li&gt;Open the message's authentication details or full headers.&lt;/li&gt;
&lt;li&gt;Record SPF.&lt;/li&gt;
&lt;li&gt;Record DKIM.&lt;/li&gt;
&lt;li&gt;Record DMARC.&lt;/li&gt;
&lt;li&gt;Record the SPF domain / Return-Path.&lt;/li&gt;
&lt;li&gt;Record the DKIM &lt;code&gt;d=&lt;/code&gt; domain.&lt;/li&gt;
&lt;li&gt;Confirm alignment with the visible From domain.&lt;/li&gt;
&lt;li&gt;Repeat after major provider or DNS changes.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Testing the actual mail flow is more useful than checking only whether a DNS record exists.&lt;/p&gt;

&lt;h2&gt;
  
  
  Gmail, Yahoo, and Microsoft Sender Requirements in 2026
&lt;/h2&gt;

&lt;p&gt;Email authentication is also a deliverability requirement for major mailbox providers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Gmail
&lt;/h3&gt;

&lt;p&gt;Google's current sender requirements say:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;All senders to personal Gmail accounts:&lt;/strong&gt; SPF &lt;strong&gt;or&lt;/strong&gt; DKIM.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Senders sending more than 5,000 messages per day to Gmail accounts:&lt;/strong&gt; SPF &lt;strong&gt;and&lt;/strong&gt; DKIM &lt;strong&gt;and&lt;/strong&gt; DMARC, plus other bulk-sender requirements.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Google recommends setting up SPF, DKIM, and DMARC even when you are below the bulk-sender threshold. Since late 2025, Gmail has been ramping up enforcement — non-compliant bulk mail now faces temporary or permanent rejection, not just the spam folder.&lt;/p&gt;

&lt;p&gt;Official guidance:&lt;br&gt;
&lt;a href="https://support.google.com/mail/answer/81126" rel="noopener noreferrer"&gt;https://support.google.com/mail/answer/81126&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Yahoo
&lt;/h3&gt;

&lt;p&gt;Yahoo's current Sender Hub says:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;All senders:&lt;/strong&gt; SPF &lt;strong&gt;or&lt;/strong&gt; DKIM at minimum.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bulk senders:&lt;/strong&gt; both SPF and DKIM, plus a valid DMARC policy with at least &lt;code&gt;p=none&lt;/code&gt;, and DMARC must pass.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Yahoo also has separate requirements for DNS, spam rates, and unsubscribe handling.&lt;/p&gt;

&lt;p&gt;Official guidance:&lt;br&gt;
&lt;a href="https://senders.yahooinc.com/best-practices/" rel="noopener noreferrer"&gt;https://senders.yahooinc.com/best-practices/&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Microsoft
&lt;/h3&gt;

&lt;p&gt;Since May 5, 2025, Microsoft rejects mail from domains sending more than 5,000 messages a day to Outlook.com, Hotmail, and Live.com addresses unless SPF and DKIM both pass and a DMARC record exists with at least &lt;code&gt;p=none&lt;/code&gt;, aligned to one of them.&lt;/p&gt;

&lt;p&gt;The original plan was to send failing mail to junk. Microsoft changed course before launch: failing messages are rejected outright with "550 5.7.515 Access denied." For a small business this usually matters when a newsletter or CRM crosses the volume line. One big campaign can put you in the stricter tier.&lt;/p&gt;

&lt;p&gt;Official guidance:&lt;br&gt;
&lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure" rel="noopener noreferrer"&gt;https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;These provider requirements do not mean every small business is a bulk sender. They do show why email authentication is now part of normal outbound-mail hygiene.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 7: Review DMARC Reports Before Changing Policy
&lt;/h2&gt;

&lt;p&gt;Once aggregate reports are arriving, use them to answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which services are sending mail using your domain?&lt;/li&gt;
&lt;li&gt;Which ones pass SPF?&lt;/li&gt;
&lt;li&gt;Which ones pass DKIM?&lt;/li&gt;
&lt;li&gt;Which ones pass DMARC?&lt;/li&gt;
&lt;li&gt;Which legitimate senders fail alignment?&lt;/li&gt;
&lt;li&gt;Are any unknown sources appearing?&lt;/li&gt;
&lt;li&gt;Are there old services you no longer use?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Do not "fix" every unknown source by authorizing it.&lt;/p&gt;

&lt;p&gt;First decide whether it is legitimate.&lt;/p&gt;

&lt;p&gt;This is where the setup-from-scratch guide ends. The next job is report interpretation and policy choice:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://bizriskguide.com/dmarc-p-none-next-steps/" rel="noopener noreferrer"&gt;DMARC p=none: What Should Your Small Business Do Next?&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  How to Know Your Setup Is Working
&lt;/h2&gt;

&lt;p&gt;Use this checklist:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;[ ] Every real sending system is listed.&lt;/li&gt;
&lt;li&gt;[ ] Current DNS settings were saved before changes.&lt;/li&gt;
&lt;li&gt;[ ] Each SPF-using domain has one SPF policy.&lt;/li&gt;
&lt;li&gt;[ ] SPF stays within the RFC lookup limit.&lt;/li&gt;
&lt;li&gt;[ ] Microsoft/Google/vendor senders are represented correctly where needed.&lt;/li&gt;
&lt;li&gt;[ ] DKIM is enabled, not just published.&lt;/li&gt;
&lt;li&gt;[ ] Real messages show the expected DKIM &lt;code&gt;d=&lt;/code&gt; domain.&lt;/li&gt;
&lt;li&gt;[ ] DMARC is published at the correct &lt;code&gt;_dmarc&lt;/code&gt; name.&lt;/li&gt;
&lt;li&gt;[ ] Aggregate reports are arriving at a monitored destination.&lt;/li&gt;
&lt;li&gt;[ ] Staff email has been tested.&lt;/li&gt;
&lt;li&gt;[ ] Invoice/accounting mail has been tested.&lt;/li&gt;
&lt;li&gt;[ ] Website mail has been tested.&lt;/li&gt;
&lt;li&gt;[ ] CRM/help-desk/marketing mail has been tested.&lt;/li&gt;
&lt;li&gt;[ ] DMARC alignment has been checked for each important flow.&lt;/li&gt;
&lt;li&gt;[ ] Unknown or failing senders are documented for review.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A green DNS checker is useful, but it is not the same as proving every important mail flow works.&lt;/p&gt;

&lt;p&gt;You can also run BizRiskGuide's free &lt;a href="https://bizriskguide.com/business-email-security-checker/" rel="noopener noreferrer"&gt;Business Email Security Checker&lt;/a&gt; against your domain for a quick outside-in view of SPF, DKIM, and DMARC.&lt;/p&gt;

&lt;h2&gt;
  
  
  What SPF, DKIM, and DMARC Will Not Protect You From
&lt;/h2&gt;

&lt;p&gt;Email authentication helps reduce direct spoofing of your domain.&lt;/p&gt;

&lt;p&gt;It does &lt;strong&gt;not&lt;/strong&gt; stop every email attack.&lt;/p&gt;

&lt;p&gt;It does not automatically prevent:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a real mailbox being compromised;&lt;/li&gt;
&lt;li&gt;a lookalike domain;&lt;/li&gt;
&lt;li&gt;display-name impersonation;&lt;/li&gt;
&lt;li&gt;phishing from another properly authenticated domain;&lt;/li&gt;
&lt;li&gt;a fraudulent message sent from an authorized compromised account;&lt;/li&gt;
&lt;li&gt;malware;&lt;/li&gt;
&lt;li&gt;malicious OAuth/app access;&lt;/li&gt;
&lt;li&gt;every form of Business Email Compromise.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For those risks, see:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bizriskguide.com/business-email-compromise-what-small-businesses-need-to-know/" rel="noopener noreferrer"&gt;Business Email Compromise: What Small Businesses Need to Know&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bizriskguide.com/how-to-secure-your-business-email-from-account-takeover/" rel="noopener noreferrer"&gt;How to Secure Your Business Email From Account Takeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bizriskguide.com/how-to-recognize-a-phishing-email-10-signs-for-small-businesses/" rel="noopener noreferrer"&gt;How to Recognize a Phishing Email: 10 Signs for Small Businesses&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For broader security basics, use the &lt;a href="https://bizriskguide.com/small-business-cybersecurity-a-practical-guide-to-protecting-your-business-in-2026/" rel="noopener noreferrer"&gt;Small Business Cybersecurity Guide 2026&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Common SPF, DKIM, and DMARC Setup Mistakes
&lt;/h2&gt;

&lt;p&gt;Avoid these:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;publishing two SPF records for the same domain;&lt;/li&gt;
&lt;li&gt;copying another company's SPF record;&lt;/li&gt;
&lt;li&gt;authorizing a vendor you do not actually use;&lt;/li&gt;
&lt;li&gt;forgetting website, invoicing, CRM, or newsletter senders;&lt;/li&gt;
&lt;li&gt;exceeding the SPF lookup limit;&lt;/li&gt;
&lt;li&gt;manually flattening SPF without a maintenance plan;&lt;/li&gt;
&lt;li&gt;publishing DKIM DNS records but never enabling signing;&lt;/li&gt;
&lt;li&gt;seeing &lt;code&gt;SPF=pass&lt;/code&gt; or &lt;code&gt;DKIM=pass&lt;/code&gt; and assuming DMARC must pass;&lt;/li&gt;
&lt;li&gt;ignoring the authenticated domains used for alignment;&lt;/li&gt;
&lt;li&gt;using a third-party sender without custom-domain authentication when it is available;&lt;/li&gt;
&lt;li&gt;publishing DMARC enforcement before testing real mail flows;&lt;/li&gt;
&lt;li&gt;using &lt;code&gt;pct=&lt;/code&gt; as if it were still part of the current RFC;&lt;/li&gt;
&lt;li&gt;assuming every domain should automatically end at &lt;code&gt;p=reject&lt;/code&gt;;&lt;/li&gt;
&lt;li&gt;adding &lt;code&gt;rua=&lt;/code&gt; but never confirming reports arrive;&lt;/li&gt;
&lt;li&gt;changing DNS without saving the old values;&lt;/li&gt;
&lt;li&gt;testing only staff email.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Free Small-Business Email Authentication Worksheet
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Sender inventory and test results
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Sending System&lt;/th&gt;
&lt;th&gt;Owner&lt;/th&gt;
&lt;th&gt;Visible From Domain&lt;/th&gt;
&lt;th&gt;Provider&lt;/th&gt;
&lt;th&gt;SPF Domain&lt;/th&gt;
&lt;th&gt;DKIM &lt;code&gt;d=&lt;/code&gt;
&lt;/th&gt;
&lt;th&gt;SPF Result&lt;/th&gt;
&lt;th&gt;DKIM Result&lt;/th&gt;
&lt;th&gt;DMARC Result&lt;/th&gt;
&lt;th&gt;Alignment?&lt;/th&gt;
&lt;th&gt;Last Test&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  DNS change log
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Date&lt;/th&gt;
&lt;th&gt;Record&lt;/th&gt;
&lt;th&gt;Previous Value&lt;/th&gt;
&lt;th&gt;New Value&lt;/th&gt;
&lt;th&gt;Reason&lt;/th&gt;
&lt;th&gt;Changed By&lt;/th&gt;
&lt;th&gt;Verified?&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  Unresolved-sender log
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Sender/System&lt;/th&gt;
&lt;th&gt;Problem&lt;/th&gt;
&lt;th&gt;Business Impact&lt;/th&gt;
&lt;th&gt;Owner&lt;/th&gt;
&lt;th&gt;Next Action&lt;/th&gt;
&lt;th&gt;Review Date&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Keep this worksheet free of passwords, API secrets, DKIM private keys, recovery codes, and other credentials.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Do I need SPF, DKIM, and DMARC if I only use Microsoft 365?
&lt;/h3&gt;

&lt;p&gt;Microsoft recommends using SPF, DKIM, and DMARC together for custom domains. First confirm that Microsoft 365 really is your only sender. Your website, invoicing platform, CRM, or newsletter service may also send as the same domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need all three if I use Google Workspace?
&lt;/h3&gt;

&lt;p&gt;Google requires at least SPF or DKIM for all senders to Gmail and stronger authentication for bulk senders. Google recommends setting up SPF, DKIM, and DMARC for your sending domains. You should also account for third-party senders.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I have more than one SPF record?
&lt;/h3&gt;

&lt;p&gt;No. If SPF is used for a domain, publish one SPF policy for that domain. Multiple SPF records cause a permanent SPF error.&lt;/p&gt;

&lt;h3&gt;
  
  
  What happens if SPF exceeds 10 DNS-query-causing terms?
&lt;/h3&gt;

&lt;p&gt;SPF evaluation returns &lt;code&gt;permerror&lt;/code&gt;. The exact delivery treatment depends on the receiver and other authentication results, but you should treat it as a configuration problem and fix the SPF design.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does a DKIM DNS record mean DKIM is working?
&lt;/h3&gt;

&lt;p&gt;No. The public record can exist while the sending service is not using it. Send a real message and check for &lt;code&gt;DKIM=pass&lt;/code&gt; and the expected &lt;code&gt;d=&lt;/code&gt; domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should a small business start DMARC at &lt;code&gt;p=none&lt;/code&gt;?
&lt;/h3&gt;

&lt;p&gt;For an established business domain where you are still discovering senders, &lt;code&gt;p=none&lt;/code&gt; is often a practical monitoring starting point. It is not a universal rule for every domain.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I move DMARC to &lt;code&gt;p=reject&lt;/code&gt;?
&lt;/h3&gt;

&lt;p&gt;Not automatically. RFC 9989 specifically cautions against automatic &lt;code&gt;p=reject&lt;/code&gt; deployment for general-purpose email domains because of indirect mail-flow issues. Review your real senders and reports before choosing a policy.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is the DMARC &lt;code&gt;pct&lt;/code&gt; tag still current in 2026?
&lt;/h3&gt;

&lt;p&gt;No. RFC 9989 removed &lt;code&gt;pct&lt;/code&gt;. Some provider documentation still shows older &lt;code&gt;pct&lt;/code&gt; examples, so check the publication date and the current RFC before copying a record.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the new DMARC &lt;code&gt;t&lt;/code&gt; tag?
&lt;/h3&gt;

&lt;p&gt;RFC 9989 adds a &lt;code&gt;t&lt;/code&gt; testing tag. &lt;code&gt;t=y&lt;/code&gt; requests test-mode handling instead of fully applying a &lt;code&gt;quarantine&lt;/code&gt; or &lt;code&gt;reject&lt;/code&gt; policy. It is not a percentage rollout tool. Small businesses do not need it for a basic &lt;code&gt;p=none&lt;/code&gt; monitoring setup.&lt;/p&gt;

&lt;h3&gt;
  
  
  How long do DNS changes take?
&lt;/h3&gt;

&lt;p&gt;It depends on the DNS provider, TTL, and receiving resolver cache. A change may appear quickly but older cached answers can remain until their TTL expires. Check the public DNS result instead of relying only on the "Saved" message in your DNS dashboard.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can SPF, DKIM, and DMARC stop Business Email Compromise?
&lt;/h3&gt;

&lt;p&gt;No. They reduce some forms of domain spoofing. They cannot stop fraud sent from a genuinely compromised mailbox or a lookalike domain that has its own valid authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do website contact forms need email authentication?
&lt;/h3&gt;

&lt;p&gt;If the form sends mail using your domain, include that mail flow in your inventory and authenticate it through the service that actually sends the message. Test both staff notifications and customer-facing confirmations.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Recommendation
&lt;/h2&gt;

&lt;p&gt;A good &lt;strong&gt;SPF DKIM DMARC setup&lt;/strong&gt; is not three DNS records copied from a tutorial.&lt;/p&gt;

&lt;p&gt;Start by finding every real sender. Save your current DNS. Build SPF carefully. Enable DKIM and prove that messages are signed. Then use DMARC to check whether the authenticated domains align with the address your customers actually see.&lt;/p&gt;

&lt;p&gt;Most important, test the mail your business really sends: staff messages, invoices, website notifications, CRM alerts, and newsletters.&lt;/p&gt;

&lt;p&gt;Once monitoring is working, use the DMARC reports to decide what should change next instead of guessing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources and References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.rfc-editor.org/rfc/rfc7208.html" rel="noopener noreferrer"&gt;RFC 7208 — Sender Policy Framework (SPF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.rfc-editor.org/rfc/rfc6376.html" rel="noopener noreferrer"&gt;RFC 6376 — DomainKeys Identified Mail (DKIM)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.rfc-editor.org/rfc/rfc9989.html" rel="noopener noreferrer"&gt;RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.rfc-editor.org/rfc/rfc9990.html" rel="noopener noreferrer"&gt;RFC 9990 — DMARC Aggregate Reporting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure" rel="noopener noreferrer"&gt;Microsoft — Set up SPF for custom cloud domains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure" rel="noopener noreferrer"&gt;Microsoft — Configure DKIM for custom domains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure" rel="noopener noreferrer"&gt;Microsoft — Configure DMARC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/a/answer/33786" rel="noopener noreferrer"&gt;Google Workspace — Set up SPF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/a/answer/174124" rel="noopener noreferrer"&gt;Google Workspace — Set up DKIM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/a/answer/2466580" rel="noopener noreferrer"&gt;Google Workspace — Set up DMARC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://support.google.com/mail/answer/81126" rel="noopener noreferrer"&gt;Google — Email sender guidelines&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://senders.yahooinc.com/best-practices/" rel="noopener noreferrer"&gt;Yahoo Sender Hub — Sender Best Practices&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Editorial fact-check note: Reviewed against current IETF, Microsoft, Google, Yahoo, and live BizRiskGuide pages on October 5, 2026. Additions this round: FortiMail CVE-2026-104286 timeliness note, Microsoft May 2025 sender-requirement enforcement (550 5.7.515 rejection), Gmail late-2025 enforcement ramp-up, Business Email Security Checker tool link.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>smallbusiness</category>
      <category>security</category>
      <category>email</category>
    </item>
  </channel>
</rss>
