Mail in Spam: Read SPF, Then DKIM, Then DMARC

Blog 3 min read

Check that the message left the server, then SPF alignment, then DKIM, then the DMARC policy. p=none does not stop forgery.

When Gmail or a company filter puts mail in spam, the first reflex is to delete SPF and write it again. The three records do not do the same job. SPF names the servers allowed to send. DKIM signs that the message was not changed on the way. DMARC tells the receiver what to do if neither one aligns with the name the reader sees. Mix up the order and you break the record that was fine.

On EuroVDC business mail the sending host is on securemail.eurovdc.eu. The records live on the nameservers that hold the zone, usually ns1.eurovdc.eu and ns2.eurovdc.eu. Opening a business email mailbox does not write the three lines for you.

Reading order

  1. Did the message leave the server. If the log has nothing, the problem is the queue or the login, not DNS.
  2. SPF result: pass, fail or permerror. Permerror is often the eleventh DNS lookup, the morning after someone added a marketing include. Count the include chain before you add another.
  3. DKIM: is there a signature, and does d= match the name you send as. A signature on someone else’s domain does not align for DMARC.
  4. DMARC last. p=none asks for reports. It does not stop a forgery. p=quarantine or p=reject acts only when neither aligned SPF nor aligned DKIM is present.

What alignment means

If the visible From is billing@company.com, the envelope that passed SPF or the DKIM d= has to share that organisational domain. A tool that sends “as you” but signs its own domain is foreign to your DMARC. The tool needs its own DNS line. You add your include, you do not paste their whole record over yours.

What not to do

  • Do not delete all three on the same afternoon and write a “clean” TXT. Read which message returned which result.
  • v=spf1 +all allows everyone. That is not a fix.
  • Moving DMARC to p=reject also cuts a legitimate tool that does not align. Read the reports, then tighten the policy.

This article and the p=none article

Why a p=none record stops no forgery is a separate article. That one is the policy that does not enforce. This one is the order for a single message already in spam: exit log, then SPF, then DKIM, then DMARC. Do not “clean up” both jobs in one edit.

Frequently asked questions

SPF passes. Why is it still spam?

Pass means the server was on the list. Content, complaint rate and a young domain are scored separately. SPF does not buy the inbox.

Must I rotate the DKIM key every year?

Rotate it if it leaked or a person with access left. Deleting a key on a calendar deletes a day of signatures. Publish the new selector, let the queue empty, then remove the old one.

Is p=none enough?

No. The record exists and enforces nothing. It collects reports. Forged mail that claims to be you still arrives.

Does EuroVDC mail reach Gmail?

It can. Gmail still runs its own filter, and that filter reads your SPF, DKIM and DMARC. If the lines are missing, you did not choose the result.

spf dkim dmarc spam email

EuroVDC

Find Your Perfect Domain Name

500+ extensions · Instant activation · Free DNS management

Search for a Domain

Did you find this content useful?

– People found it useful

Share on Social Media

Mail in Spam: Read SPF, Then DKIM, Then DMARC