Email Authentication Protocols: SPF, DKIM, DMARC, and BIMI

By Kam Low ยท Updated 2026-07-27

Email Authentication Protocols

Email authentication protocols are the standards, SPF, DKIM, DMARC, and BIMI, that verify a sender's identity and let receivers detect spoofing and phishing.

The protocols

SPF authorises sending servers. DKIM cryptographically signs messages. DMARC sets policy for failures and reports on abuse. BIMI displays a verified brand logo in the inbox, but only once DMARC is at enforcement. Together they form the modern authentication stack, covered in depth on the authentication page.

How they work together

No single protocol is sufficient alone. SPF and DKIM provide the two authentication checks, and DMARC requires at least one to pass and be aligned, then enforces policy. BIMI rewards full enforcement with brand visibility. Skipping DMARC leaves SPF and DKIM without teeth.

How Nitrosend implements them

Nitrosend provisions DKIM, MX, and verification records automatically and grades SPF, DKIM, and DMARC against the 2026 bulk-sender requirements, so the protocol stack is handled rather than hand-configured record by record.

FAQ

What are the email authentication protocols?

SPF authorises sending servers, DKIM signs messages, DMARC sets failure policy and reporting, and BIMI displays a verified brand logo once DMARC is enforced.

Which email authentication protocol is most important?

They work together, but DMARC is the keystone: it gives SPF and DKIM enforcement and reporting. Without it, the other two have no policy behind them.