How Do I Authenticate My Email? The Setup Steps

By Kam Low ยท Updated 2026-07-27

How Do I Authenticate My Email? The Setup Steps

To authenticate your email you publish three DNS records, SPF, DKIM, and DMARC, that let receiving servers verify mail from your domain is genuine.

The steps

  1. Publish an SPF record listing your sending sources, keeping under the ten-lookup limit. 2. Enable DKIM with your sending provider and publish the keys they give you. 3. Add a DMARC record at p=none to start, then tighten to quarantine and reject once reports show only your legitimate mail passing. 4. Verify alignment with a spam test email, since a pass without alignment still fails DMARC.

The mistake to avoid

Don't jump to p=reject before monitoring. Start at p=none, read the DMARC reports, confirm all your legitimate senders pass, then tighten. Going straight to reject blocks your own mail.

How Nitrosend does it for you

Nitrosend provisions DKIM, MX, and verification records automatically, and handles the subdomain-verified, apex-as-sender detail that breaks alignment when done by hand. The compliance layer then confirms the records are in place and aligned.

FAQ

How do I authenticate my email?

Publish an SPF record, enable DKIM with your provider and publish its keys, add a DMARC record starting at p=none, then verify alignment before tightening DMARC.

What order do I set up SPF, DKIM, and DMARC?

SPF and DKIM first, since DMARC depends on them, then DMARC at p=none to monitor before tightening to quarantine and reject.