
Playbook3 sections · 2 min readBy Dezső Mező · Published October 3, 2026.mdEmailDNSDeliverability
Every mail server your message passes through asks the same question: is this really from this domain, and did anyone authorize this server to send it? The answers live in three DNS records — SPF says which servers may send, DKIM signs the message so tampering shows, DMARC tells receivers what to do when the checks fail and reports the results back to you. Without them you are a stranger asking to be let in; with them you are a name on the list. This site ships all three, which is why a two-minute DNS audit is part of every contact-form deploy.
01SPF is the guest list
One TXT record listing the servers allowed to send for your domain — and the all-too-common mistake is a second SPF record instead of updating the first. Two SPF records means receivers pick neither; the fix is one record that mentions every sender: your mail provider, the site's form handler, the invoicing tool.
02DKIM is the wax seal
The sending server signs each message with a private key; receivers verify it against the public key in DNS. A signed message that arrives changed fails loudly — which is exactly what you want, because the failure lands on the forger, not on you.
03DMARC is the policy and the report
DMARC ties the two together and answers 'what if the checks fail' — monitor, quarantine or reject — plus it sends you aggregate reports of who is sending as your domain. Start with p=none watching, then tighten to quarantine, then reject. Skipping the watching phase is how legitimate mail gets locked out.
What to take away
- One SPF record, never two — merge every sender into it.
- DKIM signs the message; tampering fails the check, not you.
- DMARC starts at p=none watching, then tightens.
- A two-minute DNS audit belongs in every form deploy.
More from the lab
Browse all entries
What custom software actually costs
Custom software or off the shelf — the honest test
The first ninety days of a retainer, as it actually goes
Why clients get a progress page instead of status emails
Want this looked at on your own system?Start a conversation
