SPF, DKIM and DMARC setup serviceStop your emails landing in spam, in 2 days.

SPF, DKIM and DMARC set up and verified for your domain and every tool that sends as you.

Order now$290 fixed, 2 business days

Done by Parish Khan, senior developer since 2013
Updated

Fixed price

$290

Popular

Delivered in 2 business days after payment

  • SPF, DKIM and DMARC set up and aligned
  • Your mailbox provider plus up to 3 sending tools
  • DMARC reports in a readable dashboard
  • Gmail, Yahoo and Outlook sender rules covered
  • Verified with real test emails
Order now

Passing, or a full refund. No payment until I confirm your brief.

creators use frontends I built at Artlist and Artgrid
10M+
creators use frontends I built at Artlist and Artgrid
the year I started shipping for the web
2013
the year I started shipping for the web
products delivered for clients in 15+ countries
50+
products delivered for clients in 15+ countries
clients, with a 5-star average on Upwork and Fiverr
100+
clients, with a 5-star average on Upwork and Fiverr

Works with

  • Google Workspace
  • Microsoft 365
  • Zoho Mail
  • Any website

What changes after delivery

Right now

  • Clients tell you your invoices and replies ended up in spam.
  • Gmail or Outlook bounced your newsletter with an authentication error.
  • You are not sure which tools are allowed to send email as your domain.

After delivery

  • Your emails pass SPF, DKIM and DMARC at Gmail, Yahoo and Outlook.
  • Scammers can no longer easily send email pretending to be you.
  • Daily DMARC reports show exactly who sends email as your domain.

SPF, DKIM and DMARC checker

Enter your domain to check its email authentication live, with a plain-English list of what to fix.

Try an example:Lookups run in your browser. Nothing is stored.

I fix SPF, DKIM and DMARC for your domain and up to three sending tools, verified with real test emails, for a fixed $290.

Everything included for $290

  • DNS audit

    Every email record on your domain checked, and every service that sends email as you identified.

  • SPF, fixed

    One merged SPF record covering all your senders, under the 10-lookup limit that silently breaks many setups.

  • DKIM everywhere

    Signing turned on for your mailbox provider and up to 3 sending tools, with 2048-bit keys where supported.

  • DMARC with reports

    A DMARC record in monitoring mode, with daily reports flowing into a free dashboard you can actually read.

  • Bulk-sender checklist

    Gmail, Yahoo and Microsoft requirements checked, including one-click unsubscribe on marketing emails.

  • Verified with real sends

    Test emails to Gmail and Outlook, with the headers checked for SPF, DKIM and DMARC passes.

  • Enforcement plan

    A written, step-by-step plan to move DMARC to quarantine and then reject, without losing real email.

  • Plain-English report

    What was wrong, what changed, and exactly what to do when you add a new email tool.

Not included

  • Cleaning email lists or rewriting campaign content.
  • Recovering a damaged sender reputation. I diagnose it, but recovery takes weeks of good sending.
  • Buying a mark certificate for BIMI.
  • Setting up a new mailbox provider or migrating mailboxes.
  • A second domain. It is an add-on below.

What I need from you

  • Access to your DNS (Cloudflare, GoDaddy, Namecheap and so on), or someone who can add records.
  • Admin access to your mailbox provider, like Google Workspace or Microsoft 365.
  • A list of tools that send email as you: newsletters, CRM, website forms, invoices.

What happens to your email before the inbox

Every receiving server asks three questions. Fail them and your email lands in spam, or is rejected outright.

Your email

From: hello@yourbusiness.com

Arrives at Gmail, Outlook or Yahoo, which run three checks before deciding where it goes.

  1. 1. SPF

    Is this server allowed to send for yourbusiness.com?

    Checks the sending server against your SPF record.

  2. 2. DKIM

    Was it really signed by the domain, and unchanged?

    Verifies the signature with your public key in DNS.

  3. 3. DMARC

    Does SPF or DKIM match the From address?

    Then applies your policy if it does not.

  • Inbox

    Passes and aligns

  • Spam folder

    Fails, with p=quarantine, or a poor reputation

  • Rejected

    Fails, with p=reject, or missing rules at bulk volume

The safe DMARC rollout never jump straight to reject

  1. p=noneWeek 0

    Monitor only. Reports show every sender.

  2. p=quarantineWeeks 2 to 4

    Failures go to spam once real mail passes.

  3. p=rejectWeeks 4 to 8

    Spoofed mail is refused outright.

How delivery works

  1. Day 0

    Order and brief

    You order and list the tools that send as you. I confirm the brief and send the invoice. Work starts when payment lands.

  2. Day 1

    Audit and fix

    DNS audit, every sender identified, and SPF, DKIM and DMARC records published.

  3. Day 2

    Verify

    Test emails to Gmail and Outlook, header checks, your report and the enforcement plan.

  4. Weeks 2 to 4

    Monitor

    DMARC reports arrive in your dashboard. With the enforcement add-on, I act on them for you.

Proof, not promises

Delivered a complex e-commerce platform 2 weeks ahead of schedule. Clean code, excellent communication, and zero post-launch bugs. Will hire again.
Startup FounderUpwork Client, Client
Parish doesn't just write code. He thinks about the user, the team, and the long-term maintainability. A rare combination of speed and quality.
Product ManagerArtlist LTD, Cross-functional Peer

SPF, DKIM and DMARC setup pricing

One fixed price, agreed before any work starts. Add only what you need.

SPF, DKIM and DMARC setup

8 things included, delivered in 2 business days

$290

Optional add-ons

Your fixed price

$290

Delivered in 2 business days after payment.

Order now
  • Passing, or a full refund. If SPF, DKIM and DMARC do not all pass on test emails to Gmail and Outlook, you get a full refund.
  • No payment today. I confirm your brief, then send an invoice you pay by bank transfer in USD, EUR or GBP.

Need ongoing work instead of a one-off job? A monthly plan covers requests like this with no quotes.

The guide, 3 minute read. Updated .

On this page
  1. Why email goes to spam
  2. SPF, DKIM and DMARC explained
  3. Gmail, Yahoo and Outlook rules
  4. Rolling out DMARC safely
  5. Common mistakes
  6. Workspace and Microsoft 365
  7. BIMI logos

Why are my emails going to spam?

The most common reason is not your wording. It is that the receiving server cannot prove the email really came from you. Gmail, Yahoo and Outlook check three DNS records on your domain, SPF, DKIM and DMARC. When they are missing, broken or do not line up, your email looks exactly like a phishing attempt using your name.

Since February 2024, Gmail and Yahoo require authentication from everyone who sends to their users, with stricter rules for bulk senders. Microsoft followed for Outlook.com in May 2025. Enforcement has tightened since, which is why email that used to arrive fine can start landing in spam or bouncing without anything changing on your side.

Other causes matter too: a poor sending reputation, high spam complaints, or links to flagged domains. But authentication comes first, because without it nothing else can be trusted.

SPF, DKIM and DMARC in plain English

RecordThe question it answersWhere it livesCommon mistake
SPFIs this server allowed to send email for this domain?A TXT record on your domainTwo SPF records, or more than 10 DNS lookups
DKIMWas this email really signed by the domain, and unchanged on the way?A TXT or CNAME record per sending serviceNever switched on in the mailbox admin
DMARCDo SPF or DKIM match the visible From address, and what should happen if not?A TXT record at _dmarcMissing, or jumping straight to p=reject
dns
; SPF: one record listing every service that sends as you
example.com.                    TXT  "v=spf1 include:_spf.google.com include:servers.mcsv.net ~all"

; DKIM: a public key per sending service (the selector name varies)
google._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOC..."

; DMARC: start by monitoring, then enforce
_dmarc.example.com.             TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
What a healthy setup looks like for a domain using Google Workspace and Mailchimp.

Gmail, Yahoo and Outlook sender requirements

Everyone who sends to Gmail or Yahoo

  • Authenticate with SPF or DKIM.
  • Send from servers with valid forward and reverse DNS, over TLS.
  • Keep reported spam below 0.3% (ideally below 0.1%).

Bulk senders (about 5,000 or more emails a day)

  • Authenticate with both SPF and DKIM.
  • Publish a DMARC record (p=none is the minimum) and align it with your From domain.
  • Offer one-click unsubscribe on marketing email, and honour it within two days.
  • For Outlook.com, the same SPF, DKIM and DMARC rules apply above 5,000 emails a day since May 2025.

How to set up DMARC without breaking your email

  1. 1Monitor. Publish p=none with a reporting address. Nothing is blocked; you just start receiving daily reports from Gmail, Yahoo, Microsoft and others.
  2. 2Find every sender. Reports show every server sending as your domain. Legitimate tools you forgot, like an old CRM or invoicing app, get SPF and DKIM set up.
  3. 3Quarantine. Once real email passes, move to p=quarantine, so anything failing goes to spam instead of the inbox.
  4. 4Reject. Finally, p=reject tells receivers to refuse spoofed email outright. Your domain can no longer be used to phish your customers.

Do not jump straight to reject

Publishing p=reject before every sender passes is the fastest way to lose real email, like password resets from your app or invoices from your accounting tool. Two to four weeks of monitoring first is the safe path.

Common SPF and DKIM mistakes

  • Two SPF records. A domain may have only one. Two is an automatic failure, so every sender must be merged into a single record.
  • More than 10 lookups. Every include costs DNS lookups, and nested includes add up. Past 10, SPF fails with a permanent error.
  • DKIM never switched on. Google Workspace and Microsoft 365 both need DKIM enabled in the admin console, not just a DNS record.
  • Forgotten senders. Your newsletter tool, CRM, help desk and website forms each send as your domain and each need authentication.
  • Short keys. 1024-bit DKIM keys still work, but 2048-bit is the current recommendation wherever the provider supports it.

Google Workspace and Microsoft 365 specifics

Google Workspace: SPF uses include:_spf.google.com. DKIM is generated in the Admin console under Gmail’s “Authenticate email” setting, published as a TXT record at google._domainkey, and then switched on with “Start authentication”. That last click is the step most often missed.

Microsoft 365: SPF uses include:spf.protection.outlook.com. DKIM is enabled in the Microsoft Defender portal and needs two CNAME records, selector1 and selector2, which Microsoft rotates for you once they are in place.

BIMI: your logo next to your emails

BIMI shows your logo beside your emails in supporting inboxes like Gmail, Yahoo and Apple Mail. It only works once DMARC is at enforcement (quarantine or reject), and Gmail also requires a paid mark certificate. It is a nice finishing touch after the fundamentals, and an add-on here.

SPF, DKIM and DMARC setup FAQ

Often ordered with

Planning something bigger? Technical SEO are quoted as custom builds.

Ready when you are.

SPF, DKIM and DMARC setup for a fixed $290. Ordering takes two minutes, and there is no payment until I have confirmed your brief.

Parish Khan

You work with me directly, on a monthly plan or a fixed-price project. No agency layer, one person accountable for the build.