SPF, DKIM and DMARC Explained for WordPress Site Owners
SPF, DKIM and DMARC are DNS records that prove email sent from your domain is legitimate. SPF lists the servers allowed to send your mail, DKIM adds a cryptographic signature, and DMARC tells inboxes what to do with mail that fails those checks. Without all three, your mail is more likely to land in spam.
SPF: who is allowed to send
An SPF record is a TXT record listing every service that sends email for your domain: your email provider, your newsletter tool, your website’s SMTP service. A domain should have only one SPF record.
DKIM: proof the message wasn’t altered
DKIM adds a digital signature to outgoing mail. Your provider gives you a public key to publish in DNS, and receiving servers use it to verify the signature. Each sending service needs its own DKIM setup.
DMARC: the policy that ties them together
DMARC tells receiving servers what to do when a message fails SPF and DKIM alignment: nothing, quarantine it, or reject it. It can also send you reports showing who is sending mail as your domain.
Why this matters for WordPress
Contact forms, WooCommerce receipts and password resets are all email. If your site sends mail straight from the web server, it often fails these checks. Send site mail through an SMTP plugin connected to a proper email provider instead.
Hosting email on the same server as your website can also reveal the server’s real IP address, which lets attackers bypass a firewall like Cloudflare.
Frequently asked questions
How do I check my SPF, DKIM and DMARC records?
Use your DNS provider’s dashboard or a free DNS lookup tool, then send a test email and check the message headers for pass or fail results.
Do I need DMARC if I have SPF and DKIM?
Yes. Major mailbox providers now expect bulk senders to publish a DMARC record, and it protects your domain from spoofing.
Want it done right? Our domain email setup and audit covers all three records, SMTP and deliverability testing.