An address on your own domain looks more trustworthy than a free mailbox, and it stays with the business when staff move on. But since 2024 the big mailbox providers have been strict about one thing: proving that mail claiming to be from your domain really is. Three DNS records do that.

The three records

  • SPF (Sender Policy Framework) is a list, published in your domain's DNS, of the servers allowed to send email for your domain.
  • DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving server checks it against a public key in your DNS, which proves the message came from you and was not changed on the way.
  • DMARC tells receiving servers what to do when a message fails those checks (nothing, junk it, or reject it) and where to send reports. It also requires alignment: the domain in the visible From address must match the domain that passed SPF or DKIM.

Together they make it much harder for a criminal to send email that appears to come from your domain, the trick behind most fake invoice fraud.

What the big providers require

  • Gmail, from 1 February 2024: every sender needs SPF or DKIM, valid forward and reverse DNS, and a TLS connection, and must keep its spam rate below 0.3%. Senders of around 5,000 or more messages a day to Gmail accounts also need SPF and DKIM, a DMARC record, alignment, and one-click unsubscribe on marketing mail.
  • Yahoo introduced matching requirements at the same time.
  • Outlook.com, Hotmail and Live, from 5 May 2025: senders of more than 5,000 messages a day need SPF, DKIM and DMARC. Microsoft rejects mail that fails with the error "550 5.7.515 Access denied".

Even if you send far fewer, the same checks decide whether your quotes and invoices land in the inbox or in junk.

A safe way to set them up

  1. List everything that sends email as your domain: your mailbox provider, your website's contact form, your accounting or invoicing software, any newsletter tool.
  2. Publish one SPF record that includes all of them. A domain must have only one SPF record, and SPF allows at most 10 DNS lookups, so do not keep adding includes.
  3. Turn on DKIM in each sending service and publish the key it gives you.
  4. Start DMARC at p=none with a reporting address. This changes nothing about delivery; it shows you who is sending as your domain.
  5. Read the reports for a few weeks. Fix any legitimate sender that fails.
  6. Move to p=quarantine, then p=reject. At reject, mail forged in your name is refused outright.

Skipping straight to step 6 is how businesses accidentally block their own invoices, so take the steps in order.