SPF, DKIM and DMARC do different jobs
Three controls, one identity story—and no magic switch.
Email infrastructure / DOM/WIKI
SPF names infrastructure permitted to send for a domain. DKIM attaches a verifiable signature to a message. DMARC connects visible sender identity to those checks and states how receivers should handle failures.
Deploy them in that order, but observe before enforcing. Inventory every legitimate sender, rotate keys deliberately and read aggregate reports for unknown sources or alignment gaps.
Authentication supports trust; it does not create consent. Permission, relevant content, suppression handling and easy opt-out remain separate operating responsibilities.
This article is general editorial information, not professional or transaction-specific advice.