Deliverability · How-to

How to set up SPF, DKIM & DMARC (step-by-step)

Bluey Email team·Updated 2026-07-12·9 min read
The short version

Add three DNS records to your domain: an SPF record listing who can send for you, a DKIM record (given by your email tool) that signs your mail, and a DMARC record at _dmarc.yourdomain.com that starts at p=none for monitoring. Add them at your DNS host, wait for them to spread, then send a test to confirm. Budget 15–20 minutes.

This is the hands-on version of one step in our complete guide to email deliverability. Since 2024, Gmail, Yahoo and Microsoft reject bulk email that isn't authenticated — it never reaches the inbox or even the spam folder. These three records prove your mail is really from you. You set them up once.

You shouldn't need to worry about the intricacies of email security standards, but you should be able to confidently rely on an email's source.
NKNeil KumaranGroup Product Manager, Gmail Security & Trust, GoogleSource
Before you start: log in to wherever your domain's DNS lives (your registrar or host), and copy the exact SPF/DKIM values from your email tool's settings. In Bluey they're under Settings → Sending domains.

Step 1 — Add your SPF record

SPF lists the servers allowed to send for you.

Add one TXT record at your root domain. If you already have an SPF record, don't add a second one — merge the includes into the existing record. Use ~all (soft fail) while testing, then tighten to -all once everything delivers.

Step 2 — Add your DKIM record

DKIM signs your mail so it can't be faked.

Your email tool gives you a public key and a “selector.” Publish it exactly as shown (usually a CNAME record). The key is long — paste it verbatim.

The #1 DKIM mistake: your DNS host quietly adds your domain twice (like bluey._domainkey.yourdomain.com.yourdomain.com). Paste only the host your tool specifies.

Step 3 — Add your DMARC record

DMARC ties it together and always starts at p=none.

DMARC tells inbox providers what to do with mail that fails, and emails you reports. Always start at p=none (monitor only) so you don't block your own real mail. After 1–2 weeks of clean reports, move to p=quarantine, then p=reject.

Step 4 — Verify it works

Send a test and read the headers.

  • Use your tool's domain checker (Bluey shows a green tick per record).
  • Send a test to a Gmail address, open it, click Show original, and confirm SPF, DKIM and DMARC all say PASS.
  • Or run your domain through a free DMARC/SPF lookup tool.
All three PASS? You're authenticated. Next, work through the Gmail & Yahoo sender requirements checklist to make sure you meet the rest of the 2026 rules.

Authentication checklist

One SPF TXT record at the root (merge, don't duplicate)
DKIM record pasted exactly as your tool specifies
DMARC record at _dmarc, starting at p=none
Test email shows SPF + DKIM + DMARC = PASS
One-click unsubscribe enabled

Domain authentication checklist (PDF)

A printable one-pager with the exact records and the p=none → p=reject ramp.

  • Exact host fields for SPF, DKIM, DMARC
  • The safe DMARC ramp
  • A 2026 Gmail/Yahoo compliance check
Free download

Start your free trial and we’ll email the download to your inbox.

Start free and get it

Common questions

Do I need all three records?

Yes. In 2026, major inbox providers require SPF, DKIM and DMARC for bulk senders and reject mail that fails. Together they prove your identity and protect your domain from spoofing.

How long until they take effect?

DNS changes take anywhere from a few minutes to 48 hours to spread, depending on your host. Most are live within an hour.

Will this stop my emails going to spam?

It's the essential foundation, but not the whole story. Authentication gets you delivered; engagement and list hygiene keep you in the inbox.

What's the safest DMARC policy to start with?

p=none. It monitors and reports without affecting delivery, so you can confirm your real mail passes before tightening to quarantine or reject.

Free · 7 days

Start sending in an afternoon.

Spin up Bluey free, get your email trusted, and send your first campaign today.

Sources: 2026 bulk-sender authentication and one-click-unsubscribe requirements, and the Neil Kumaran quote — Google/Gmail blog (Oct 2023). Record values shown are illustrative; use the exact values from your own tool and DNS host.