On this page
What email authentication covers
Email authentication is a set of DNS-based standards that let a receiving server check whether a message claiming to be from your domain really is. Each standard answers a different question, and they only protect you fully when they work together and align with the From address your recipients see.
| Standard | Question it answers |
|---|---|
| SPF | Is this server allowed to send for the return-path domain? |
| DKIM | Was this message signed by the domain, and is it unaltered? |
| DMARC | Do SPF or DKIM align with the From domain, and what should happen if not? |
| BIMI | Can the brand’s verified logo be shown next to the message? |
Why it matters more than ever
Since 2024, Gmail and Yahoo have required bulk senders to authenticate with SPF and DKIM, publish a DMARC record with alignment, offer one-click unsubscribe on marketing mail and keep complaint rates low. Other providers apply similar expectations. Authentication has moved from best practice to a basic condition for reaching the inbox with permission-based mail. It also protects your customers from phishing that uses your name.
Where most setups have gaps
The main domain’s office email is often authenticated correctly. The gaps are elsewhere:
- A CRM, helpdesk or invoicing tool sending as your domain with no custom DKIM.
- A website contact form sending through the web server’s local mail function.
- Marketing platforms signing with their own domain, so DMARC never aligns.
- Subdomains with no records at all.
- An SPF record that has exceeded its lookup limit.
What’s included
- A complete inventory of sending sources, found through DMARC reports, headers and conversations with your team.
- SPF records built for each sending domain within the lookup limit.
- Custom DKIM on every platform, signing with your domain.
- DMARC with reporting, rolled out from monitoring towards enforcement.
- BIMI where your DMARC policy and brand assets support it.
- MTA-STS and TLS-RPT for inbound transport security where useful.
- A verification report showing real headers from test sends to major providers.
How we deliver it
- Publish or review DMARC in monitoring mode to see who is sending as you.
- Identify every legitimate source and flag unknown ones.
- Configure SPF and DKIM on each source, aligning with your From domain.
- Send test messages from every source and record Authentication-Results headers.
- Move DMARC through quarantine to reject as reports confirm legitimate mail passes.
- Add BIMI once enforcement is in place and the logo requirements are met.
- Hand over documentation and, if you want, ongoing report monitoring.
A note on BIMI
BIMI lets supporting mailbox providers display your logo beside authenticated messages. It requires DMARC at quarantine or reject, a logo in a specific SVG format, and for some providers a Verified Mark Certificate or Common Mark Certificate, which in turn may depend on trademark status. It’s a trust and branding signal, not a deliverability shortcut, so we recommend it only when the foundations are solid.
What affects timeline and cost
- Number of domains, subdomains and sending sources.
- Platforms that don’t support custom DKIM or return-path domains.
- How long DMARC monitoring needs before enforcement.
- Whether BIMI, MTA-STS and TLS-RPT are in scope.
For individual pieces, see SPF configuration, DKIM configuration and DMARC configuration.
Common mistakes
Treating authentication as a one-off DNS job rather than an inventory of every sender. Declaring success because the main mailbox passes. Enforcing DMARC before third-party tools align. Pursuing BIMI while DMARC is still at p=none. Never revisiting the setup when a new tool is added.
Read the email infrastructure guide, browse email infrastructure services, or contact us.
Frequently asked questions
Is SPF and DKIM enough without DMARC?
Not any more for bulk senders to major providers, and not for protecting your domain from spoofing. DMARC ties them to your visible From address.
How do you prove authentication works?
We send real messages from every source to test accounts at major providers and share the Authentication-Results headers showing pass and alignment.
Does BIMI guarantee our logo appears?
No. Display depends on each provider’s rules, certificates and reputation. BIMI makes you eligible; the provider decides.
How often should authentication be reviewed?
Whenever you add or remove a sending tool, and periodically through DMARC reports, which show new or failing sources.
Can you authenticate mail sent by our website or CRM?
Yes. We route website mail through an authenticated sending service rather than the web server’s local mail function, and configure custom DKIM and return-path domains on your CRM.
Talk to us about email authentication
SPF, DKIM, DMARC and BIMI aligned and verified end to end.