Stop scammers sending fake emails that look like they come from your domain. Pick your email provider, choose your policy, and copy the exact DNS records to paste into your domain settings. Free, instant, nothing uploaded.
Authorises who can send email for your domain. One SPF record per domain.
Tells receivers what to do with fake mail β and sends you reports.
DKIM is the third piece β it's a signing key your email provider gives you (Google, Microsoft, etc. each have a setup page). Turn it on in your provider's admin for full protection.
SPF and DMARC are just two of the checks. I'll audit your whole exposure β leaked passwords, spoofable email, dark-web mentions, website gaps β and hand you a plain-English report.
Get a Digital Exposure Audit βSPF lists which servers may send email for your domain. DKIM adds a cryptographic signature so receivers can verify the message wasn't tampered with. DMARC ties them together and tells receivers what to do when a message fails β and emails you reports so you can see who's trying to spoof you.
Add the SPF record as a TXT record at your domain root (Name @), and the DMARC record as a TXT record at Name _dmarc. Start DMARC at p=none to watch safely, then tighten to p=quarantine and p=reject once you've confirmed your real mail passes.
A DNS TXT record that lists which mail servers are allowed to send email for your domain, so mailbox providers can reject forged mail claiming to be from you.
A DNS TXT record at _dmarc.yourdomain that tells receiving servers what to do with mail that fails SPF or DKIM β monitor, quarantine or reject β and where to send reports.
In your domain's DNS zone at your registrar or host (Hostinger, Cloudflare, GoDaddy, etc.). SPF goes at the root (Name @); DMARC goes at Name _dmarc.
Yes β start at p=none (monitor) so nothing is blocked while you confirm your legitimate mail passes. After a couple of weeks of clean reports, tighten to p=quarantine, then p=reject.