SPF, DKIM and DMARC in 2026: The Email Setup Every Small Business Domain Needs

SPF, DKIM and DMARC: the email setup every small business domain needs

If your invoices, quotes or newsletters have started landing in spam, or bouncing back with errors like “550 5.7.515”, the problem is probably not what you wrote. It is your domain’s email authentication: SPF, DKIM and DMARC. Gmail, Yahoo and Microsoft Outlook have spent the last two years tightening their rules, and in 2026 email that fails them is far more likely to be rejected outright.

This guide explains SPF, DKIM and DMARC in plain English, what the big inbox providers require right now, and how to set all three up on a small business domain without breaking the email you already send.

What SPF, DKIM and DMARC actually do

Think of them as three checks a receiving mail server runs on every email that claims to come from your domain:

  • SPF (Sender Policy Framework) is a list of the servers allowed to send email for your domain. It lives in a TXT record in your DNS.
  • DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving server checks it against a public key published in your DNS, which proves the email wasn’t changed on the way and came from an authorised sender.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the two together. It tells receivers what to do when a message fails (nothing, spam folder or reject) and sends you reports about who is sending email as your domain.

SPF and DKIM prove a message is legitimate. DMARC checks that the domain they prove matches the domain in the From address people actually see, known as alignment. Without it, a scammer could pass SPF with their own domain and still put your business name in the From line.

What Gmail, Yahoo and Outlook require in 2026

The big three now have broadly the same rules. According to Red Sift’s 2026 sender requirements guide:

  • Bulk senders (roughly 5,000 or more emails a day to personal Gmail, Yahoo or Outlook.com addresses) must pass both SPF and DKIM, publish a DMARC record of at least p=none that aligns with the From domain, offer one-click unsubscribe on marketing email, and keep spam complaints below 0.3%, ideally under 0.1%.
  • Gmail moved from temporary deferrals to permanent rejections of non-compliant bulk mail in November 2025.
  • Microsoft began enforcing the same requirements for Outlook.com, Hotmail and Live addresses in May 2025, and rejects failing mail rather than quietly sending it to junk.

Even if you send far fewer than 5,000 emails a day, Gmail expects every sender to use SPF or DKIM and to keep spam rates low. As GMass explains, the hard rejections are driven mainly by authentication and alignment failures. In practice, a small business with SPF, DKIM and DMARC set up properly has far fewer deliverability problems than one relying on luck.

Before you start: list everything that sends as your domain

This is the step most people skip, and it is the reason DMARC setups break things. Make a list of every service that sends email with your domain in the From address:

  • Your mailbox provider (Google Workspace or Microsoft 365)
  • Your email marketing tool (Mailchimp, Klaviyo, Brevo and so on)
  • Your CRM or booking system
  • Your website, for contact form notifications and WooCommerce order emails
  • Invoicing and accounting software
  • Helpdesk or support tools

Each of these needs to be covered by SPF, DKIM or both. Most providers have a “domain authentication” page in their settings that gives you the exact records to add.

Step 1: Set up SPF

Your domain should have exactly one SPF record. It is a TXT record at the root of your domain that looks something like this:

v=spf1 include:_spf.google.com include:servers.mcsv.net ~all
  • Each include: adds a service that is allowed to send for you. Use the exact value your provider gives you.
  • ~all (soft fail) is the safe default while you are setting things up. -all (hard fail) is stricter.
  • If you find two SPF records, merge them into one. Two records make SPF fail completely.
  • SPF allows a maximum of 10 DNS lookups. Every include counts, and some includes contain more includes. If you use lots of tools, rely on DKIM for them rather than stacking includes.

Step 2: Turn on DKIM for every sender

DKIM is switched on inside each sending service, not just in DNS. In Google Workspace it is in the Admin console under Apps, Google Workspace, Gmail, Authenticate email. In Microsoft 365 it is in the Defender portal under the email authentication settings. Your marketing tool and CRM will give you CNAME or TXT records to add.

Once the records are published, go back to each tool and click verify. DKIM is the sturdier of the two checks because it usually survives forwarding, so make sure every service that sends as your domain signs with it.

Step 3: Publish a DMARC record in monitoring mode

DMARC is a TXT record at _dmarc.yourdomain.com. Start with a policy that only monitors:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  • p=none means receivers take no action on failures yet. It meets the minimum requirement for bulk senders.
  • rua is where the daily aggregate reports go. They arrive as XML files, so use a DMARC report reader to turn them into something readable. Several have free plans for small domains.

Leave this running for two to four weeks. The reports will show every service sending as your domain, including ones you forgot about, and whether each one passes.

Step 4: Fix what fails, then tighten the policy

Once your reports show all your real senders passing, move up in stages:

  1. p=quarantine; pct=25 sends a quarter of failing mail to spam.
  2. p=quarantine sends all failing mail to spam.
  3. p=reject blocks failing mail, once you are confident nothing legitimate is failing.

A p=reject policy is the strongest protection against people spoofing your domain in phishing emails, which matters a lot if customers pay you by invoice or bank transfer. None of the big providers require it yet, but it is where you want to end up.

Common SPF, DKIM and DMARC problems on small business domains

  • Website emails going to spam. By default WordPress sends contact form and order emails straight from your web server, which usually fails SPF and DKIM. Install an SMTP plugin and send through your mailbox provider or a transactional email service. Add it to the list in our WordPress security and backup checklist, and if you are planning an update, our WordPress 7.0 guide covers what else to check.
  • A second SPF record added by a new tool. Merge it into the existing record.
  • Marketing emails passing SPF but failing DMARC. The tool is sending from its own domain behind the scenes. Set up its custom domain or DKIM authentication so it aligns with yours.
  • Forgotten tools. DMARC reports often reveal an old CRM or form builder still sending. Either authenticate it or switch it off.

If you send emails from forms or CRMs through automation tools, check which domain they send from too. Our Zapier vs Make vs n8n comparison covers how those tools fit into a small business stack.

Why this matters before the holidays

Q4 is when most small businesses send the most email, and when inbox providers are least forgiving. If you are planning promotional emails around Black Friday and Small Business Saturday, get your records sorted in October so any problems show up before the big sends. Make sure one-click unsubscribe is switched on for your marketing emails too; most email platforms now add it automatically.

Common questions

Do I need DMARC if I only send a few emails a day?

The strictest rules only apply to bulk senders, but DMARC is still worth having. It protects your domain from being spoofed and helps your everyday email reach the inbox.

Can I have more than one SPF record?

No. A domain must have a single SPF record. If you have two, SPF fails. Combine them into one record with multiple includes.

How long does it take to set up SPF, DKIM and DMARC?

Adding the records usually takes under an hour. The DMARC monitoring phase should then run for a few weeks before you move to quarantine or reject.

What does error 550 5.7.515 mean?

It is Microsoft’s rejection code for mail from a domain that doesn’t meet its authentication requirements. Check that SPF and DKIM pass and that you have a DMARC record.

The short version

Set up SPF and DKIM for every service that sends as your domain, publish a DMARC record at p=none, read the reports for a few weeks, then move towards p=reject. It is an afternoon of DNS work, and it stops invoices, quotes and campaigns from quietly disappearing into spam.

Written by

Prem

Guest contributor on GuestPosts.

Leave a Reply

Your email address will not be published. Required fields are marked *