Help center
Email authentication
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI checks with the record to publish, DMARC report intake and diagnostics, DMARC alerts, and managed records.
Updated · 5 articles
Email is the part of a domain that gets forged. DomainGuard reads the records that stop that (SPF, DKIM, DMARC), the ones that protect delivery (MX, MTA-STS, TLS-RPT), the optional BIMI record, and, on paid plans, the aggregate reports receivers send back about who is sending as you.
Articles
- SPF, DKIM and DMARC checks - the records as published, Pass / Review / Fail, and the exact record to paste.
- MX, MTA-STS, TLS-RPT and BIMI - where mail is delivered and the transport-security records around it.
- DMARC reports - the report inbox DomainGuard hosts, the senders it reveals, the 30-day summary, rotating the address, and the alerts (Starter and up).
- DMARC setup checklist and diagnostics - the five-step setup status, the ranked "why is my mail in spam" diagnostic, and the two-week / 95% rule for tightening policy.
- Managed email authentication - CNAME your
_dmarcrecord to DomainGuard and let it advance the policy for you; SPF flattening.
Where
- Web: a domain's Email & DMARC module; Monitor, DMARC for the account-wide report view.
- iOS: the Email & DMARC module on a domain's page: three cards (SPF, DKIM, DMARC) plus MX, each with a one-line explanation and a page behind it.
- API/MCP:
GET /api/domains/:id/email-security,/api/dmarc/*; toolsget_domain_email_security,get_dmarc_summary,get_dmarc_diagnostics,get_dmarc_setup_status,get_dmarc_senders,get_dmarc_inbox.
The record checks are free on every plan. Receiving and reading aggregate reports starts at Starter.
The order to do things in
- SPF: publish the record naming every service that sends as you, and keep it under 10 lookups.
- DKIM: turn on signing at each sending service and publish its key.
- DMARC at
p=nonewith DomainGuard's report address, so nothing is blocked while you watch. - Read the reports for two weeks. Add any legitimate sender that fails to SPF or DKIM.
- Tighten to
quarantine, thenreject, once 95% of mail aligns.
Every step has the exact record to paste, and the setup checklist shows which step you are on.
Common questions
Will DMARC stop phishing sent to me? No. It stops other people sending as your domain. Inbound filtering is a different product.
Do I need to understand the records? No. Each card explains what the record does in one line, and the record to publish is generated for you.
In reading order
Articles in Email authentication
- SPF, DKIM and DMARC checksHow each record is read and graded, what Pass / Review / Fail mean, the recommended record with a Copy button, and the two DMARC policies labelled honestly.Updated
- MX, MTA-STS, TLS-RPT and BIMIWhere your mail is delivered, the records that force encrypted delivery and report on failures, and the optional brand-logo record.Updated
- DMARC reportsThe report address DomainGuard hosts for you, what aggregate reports reveal about who sends as your domain, the 30-day summary, rotation, and alerts.Updated
- DMARC setup checklist and deliverability diagnosticsThe five-step setup status, the ranked diagnostic that answers why mail is going to spam, and the two-week / 95% rule before tightening policy.Updated
- Managed email authenticationDelegate your DMARC record to DomainGuard with one CNAME so the policy can be advanced without further DNS edits, and let DomainGuard flatten your SPF.Updated
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
