Email deliverability: SPF, DKIM and DMARC explained
A plain-language guide to the three DNS records that decide whether your emails reach the inbox or the spam folder.
Email deliverability: SPF, DKIM and DMARC explained
Email is still the highest-ROI channel for most B2B companies. But it only works if messages arrive in the inbox. Three DNS records control that outcome: SPF, DKIM and DMARC.
This article explains what each does, why it matters and how to set them up for HubSpot, Google Workspace or any outbound platform.
SPF: who can send for your domain?
Sender Policy Framework tells receiving servers which IP addresses and platforms are allowed to send email for your domain. Without it, spammers can spoof your domain and your legitimate emails look suspicious.
A typical SPF record lists your mail server, HubSpot, Microsoft 365 and any other sending service as authorized senders.
DKIM: proving the message was not altered
DomainKeys Identified Mail adds a digital signature to every email. The receiving server checks the signature against a public key published in your DNS. If they match, the message is authentic and unmodified.
DMARC: what to do when checks fail
DMARC tells inbox providers what to do if SPF or DKIM fail: none, quarantine or reject. It also sends back reports so you can see who is trying to send as your domain.
Start with a relaxed policy, review reports for two weeks, then move to quarantine or reject.
Why this matters for CRM
HubSpot marketing emails, sales sequences and automated notifications all use your domain reputation. If your DNS records are wrong, even your best leads never see the message.
Setup takes under an hour. The payoff is higher open rates, fewer spam complaints and a sender reputation that compounds over time.
Want a second pair of eyes on your CRM?
We run free 15-minute reviews โ no slides, no pitch, just a look at your setup.
Book a review โ