Anyone can send an email pretending to be you. Nothing in the original design of email stops it. Three settings were added over the years to fix that, and Gmail, Yahoo and Microsoft now require them.
If they are missing or wrong, your mail gets junked or rejected. Most setups have at least one of the three wrong, and nothing anywhere tells you.
What usually goes wrong
One record is missing
Very common on new domains, and on any domain where someone added a new tool without updating the settings.
The record is too long
There’s a hidden limit. Add a CRM and a helpdesk and you quietly cross it. The setting still looks perfect.
Everything passes, mail still fails
The checks pass for the wrong domain. This is the most common fault I find, and there are only two fixes.
What I do
Set all three properly on every domain you send from, then prove they work.
1. SPF — who can send as you
This lists the services allowed to send email using your domain. Most people copy one from a blog post and never touch it again.
There’s a limit of ten lookups. Google, your sending tool, a CRM and a helpdesk together will push you over it — and past the limit, the whole thing is treated as broken. I build yours from the services that actually send for you and count it.
2. DKIM — a signature on every email
This adds a hidden signature so a receiver can prove the message really came from you and wasn’t altered on the way.
It’s the more reliable of the three, because it still works when someone forwards your email. Each provider needs its own key, so a domain sending through two tools needs two.
3. DMARC — what to do if the checks fail
This tells Gmail what to do when the first two fail: ignore it, send to spam, or reject it outright. It also emails you a daily report on what receivers saw.
Most domains sit on “ignore it” for years while the owner believes they’re protected. I start there deliberately, read the reports for a few weeks so nothing legitimate breaks, then turn it up.
4. Check every domain, not just one
If you run a fleet, all of them get checked in one pass. I’ve found things like an entire batch of inboxes with no signature at all, quietly killing results for months.
How long it takes
What I need from you
Two things, and the second is the one people forget.
Your domains
Every domain you send from, not just the main one.
Everything else that sends
Your CRM, helpdesk, invoicing tool, newsletter. If I don’t know about them, turning on protection will break them.
Domain access
Or approval to make the changes with you watching on a call.
A recent bad email
If mail is currently going to spam, one example tells me a lot.
Is this right for you?
This is a good fit
- You’re starting cold email and want it set up right
- Gmail or Outlook started rejecting your mail
- You have lots of domains and no idea which are protected
- Someone told you to “set up DMARC” and you don’t know where to start
Look elsewhere
- You only send from one inbox and never send in bulk
- You want it done today and you have twenty tools sending as you
What it costs
Priced on how many domains and how many other tools send as you. A single domain is a small job.
Check it yourself first
These are free and run in your browser. If they answer your question, you don’t need me.
Common questions
Is DMARC actually required?
For anyone sending in bulk to Gmail, Yahoo or Microsoft, effectively yes. The bare minimum passes their check, but it protects nothing — which is why most domains that “have DMARC” are not actually protected.
Why does my email fail when SPF and DKIM both pass?
Because they’re passing for your sending tool’s domain, not yours. The receiver checks that they match the name your recipient sees. There are two ways to fix it and I’ll set up whichever fits your tool.
Can you fix a record that’s over the limit?
Yes. It usually means removing services that no longer send, combining a few, or moving one onto its own sub-domain so it stops eating the budget.
Will turning this on break my other emails?
Not if it’s done in stages, which is exactly why I read the reports before turning protection up. That waiting period is the safety step.
Last reviewed
Other things I do
Send me your domain list
I’ll tell you which are actually protected, which only look protected, and what it takes to close the gap.
What happens on the call
We look at your setup together, I tell you what’s wrong and what it takes to fix. If you can do it yourself, I’ll say so — that happens fairly often, and it’s fine.