SPF, DKIM and DMARC: E-mail protection clearly classified

Sep 20, 2026 | Security

By Herbert Röblreiter

SPF, DKIM and DMARC are three different building blocks for more credible email communication. They do not replace good passwords or a security culture, but they do reduce the likelihood that third-party systems can send messages on behalf of your domain.

SPF: Which systems are allowed to send?

An SPF entry determines which mail servers are generally allowed to send for a domain. This is particularly important if you are using Microsoft 365, Google Workspace, a newsletter system, a ticket system or your own mail server at the same time. It is crucial that all permitted shipping routes are clearly recorded.

DKIM: Assign messages cryptographically

DKIM provides outgoing emails with a signature. Receiving servers can use this to check whether the message was actually sent via an authorized system and was not changed along the way. Multiple DKIM keys are normal for multiple shipping platforms.

DMARC: Specify how to deal with abnormalities

DMARC connects the checks and defines a policy. You often start with observation, evaluate reports and only then gradually tighten the guidelines. This prevents legitimately sent messages from being unintentionally rejected.

Module Task
SPF Define permitted shipping sources
DKIM Technically sign sender and integrity
DMARC Evaluate checks and control policies

What is often overlooked is

Today, a domain often has more shipping channels than expected: online forms, ERP systems, scanners, monitoring, accounting software or external service providers. Therefore, the configuration should not be set once and forgotten. Changes to platforms and new senders belong in a comprehensible process.

DAXS supports the recording of existing shipping channels, DNS configuration, monitoring and the coordinated expansion of SPF, DKIM and DMARC. This is a possible service component and is not automatically part of every care.

Verwandte Artikel

No Results Found

The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.

0 Comments