What is SPF, DKIM, and DMARC? Three DNS records that prove your email is really from you, not someone pretending to be you. Nearly 86 percent of Southwest Michigan business domains have no DMARC enforcement at all, according to Parallax Intelligence's audit of 435 local domains. Gmail, Outlook, and Yahoo treat those domains as suspicious by default. If your Battle Creek or Kalamazoo business has never touched these settings, this guide explains what each record does and what to fix first.
What is SPF and what does it do?
SPF is your domain's approved sender list.
Think of it like a staff directory a mail server checks before it lets a delivery in. Your SPF record lives in your DNS and lists every service allowed to send email as your domain, your email provider, your CRM, your invoicing tool, your contact form. When a message arrives claiming to be from you, the receiving server looks up that list. If the sending server isn't on it, SPF fails.
SPF is fast to set up and it catches a lot of obvious spoofing. But it has a real weak spot: it breaks when an email gets forwarded, because the forwarding server isn't on your approved list either. That's exactly what DKIM is for.
What is DKIM and how does it sign your email?
DKIM is a digital seal attached to every message you send.
Each outbound email gets signed with a private key only your mail server holds. The receiving server checks that signature against a public key sitting in your DNS. If the message was altered in transit, even by one character, the signature breaks and the check fails. If it matches, the receiving server knows the email is untouched and genuinely came from your systems.
Unlike SPF, DKIM survives forwarding. The signature travels with the message itself, not the server that delivered it. That's why most real setups need both, not just one. Cloudflare's Learning Center breaks down the technical mechanics if you want to go deeper.
What is DMARC and how does it use SPF and DKIM together?
DMARC is the rule that tells receiving servers what to do when SPF or DKIM fails.
Without DMARC, every mail server makes its own call on a failed message. Some quarantine it. Some deliver it anyway. Some reject it. DMARC removes the guesswork with a policy you set yourself, and it comes in three levels. "None" means monitor and report, but deliver anyway. "Quarantine" sends failures to spam. "Reject" blocks them outright. Since February 2024, Google has required SPF, DKIM, and DMARC for any domain sending 5,000 or more emails a day to Gmail addresses, according to Google's sender requirements. Microsoft added its own enforcement in May 2025.
Why do you need all three, not just one?
Because each one closes a different gap, and a spoofer only needs to find the gap you left open.
SPF alone still lets someone spoof your "From" address on a server your SPF record allows for something else. DKIM alone proves a message wasn't altered, but it doesn't tell anyone what to do if a message shows up without a valid signature at all. DMARC alone has nothing to enforce; it needs SPF and DKIM results to actually evaluate. Run all three together and each one backs up the others.
What happens to Michigan businesses without DMARC?
The gap is bigger than most owners assume, and it's not hypothetical.
That figure from our Southwest Michigan audit means nearly nine out of ten local business domains have no policy telling Gmail or Outlook what to do with a message that fails authentication. The full county-by-county breakdown is in the Southwest Michigan Email Security Report. Meanwhile, the FBI Internet Crime Complaint Center's 2025 Annual Report put business email compromise losses at just over 3 billion dollars nationally in 2025, the second-costliest cybercrime category the Bureau tracks. An unenforced domain is an open door. Someone could send a fake invoice under your business name right now and you'd have no way to stop it.
How do you set up SPF, DKIM, and DMARC for your business?
You've got two real paths, and neither is complicated once you know the order.
The DIY path: log into your domain's DNS panel, wherever you registered it, GoDaddy, Bluehost, or your host of choice, and add the SPF record your email provider publishes, then turn on DKIM signing in your provider's admin console, then add a DMARC record starting at "p=none" so you can watch reports before enforcing anything. Order matters. SPF first, then DKIM, then DMARC.
The done-for-you path: Parallax's DMARC audit service checks your current setup, tells you exactly what's missing, and handles the DNS changes in the right order. If you'd rather not touch DNS settings yourself, that's what it's for. Call (269) 460-1772 to start with the free domain check.
How long does it take, and is DMARC actually required?
Most single-provider setups take under an hour once you have DNS access; stepping up DMARC enforcement safely takes a few weeks of watching reports first.
DMARC is legally required only if you send 5,000 or more emails a day to Gmail or Yahoo addresses. For everyone else, it's best practice, not a mandate, but the cost of skipping it is the same either way: emails that don't arrive and a domain anyone can impersonate. If your quotes are already landing in spam, why emails aren't reaching customers walks through the symptoms and the fix. If you want the plain-language DNS steps, how to stop quotes going to spam covers the setup end to end.
If you run a business in Battle Creek, Kalamazoo, or anywhere in Southwest Michigan and want someone else to handle the DNS changes, the free domain check at (269) 460-1772 is a good place to start.