Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Reliable email authentication requires four related but separate pieces: SPF authorizes sending hosts for an SMTP identity, DKIM verifies a domain’s message signature, DMARC checks whether SPF or DKIM authenticated a domain aligned with the visible From address, and PTR maps a sending IP address back to a hostname. Configure each at the level you control: usually DNS for SPF, DKIM and DMARC, and the sending-IP owner or hosting provider for PTR.

What SPF, DKIM, DMARC and PTR each do

These records and checks work together, but they do not prove the same thing. SPF and DKIM provide authentication results; DMARC evaluates those results against the domain recipients see; PTR is reverse DNS for the sending IP.

Component What it checks or provides Where it is configured
SPF Whether a sending host is authorized for the SMTP HELO or MAIL FROM identity A DNS TXT policy at the domain being checked
DKIM Whether a message carries a verifiable signature associated with a signing domain A signing service plus the matching public key in DNS, identified by a selector
DMARC Whether SPF or DKIM passed with an authenticated domain aligned to the message’s Author Domain; it also communicates handling preferences and can request reports A DNS policy for the Author Domain
PTR The reverse-DNS name associated with a sending IP address Reverse-DNS configuration controlled by the IP owner or its host

SPF authorizes an SMTP identity, not the visible From address

SPF evaluates the domain in the SMTP HELO or MAIL FROM identity. Those identities are part of the mail transaction and are not necessarily the same as the address in the message’s visible From header. SPF passing alone therefore does not authenticate the visible From domain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DKIM verifies a domain’s signature

A sending service can sign a message with a private key. A recipient uses the signature’s signing domain and selector to find the corresponding public key in DNS and verify the signature. The selector lets a domain manage distinct keys and replace them over time; the DNS key must match the key the service is using to sign.

DMARC connects authentication to the visible author domain

DMARC evaluates whether at least one of two paths succeeds: SPF passes and its authenticated domain aligns with the message’s Author Domain, or DKIM passes and its signing domain aligns with that Author Domain. Alignment can be relaxed or strict. A DMARC policy also expresses a message-handling preference for failed validation and can request reports; it does not create SPF or DKIM authentication by itself.

PTR is reverse DNS for an IP address

A PTR record associates a sending IP with a hostname through reverse DNS. It is generally managed by the organization that controls the IP range or by the server host—not simply by whoever edits the sending domain’s ordinary DNS zone. A dynamically allocated SMTP client may not have a reverse mapping, as RFC 5321 notes.

Rank #2
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

How to set up SPF, DKIM and DMARC

  1. Inventory every approved sender. List the systems that send using the domain, including business mail, transactional messages, marketing services and support tools. Have the domain owner confirm the list before publishing a restrictive SPF policy; omitting an authorized sender can cause its mail to fail SPF.
  2. Publish one SPF TXT policy for each relevant SMTP identity domain. Build the policy around the actual approved senders for the MAIL FROM and, where applicable, HELO domains. RFC 7208 permits only one SPF record at an owner name, so combine authorized senders in one policy rather than publishing multiple SPF records there.
  3. Check SPF DNS-querying terms. RFC 7208 limits processing to ten DNS-querying terms. Review nested include, a, mx, ptr, exists and redirect mechanisms or modifiers as well as the terms in the top-level policy. Do not add SPF’s ptr mechanism: RFC 7208 section 5.5 says, “This mechanism SHOULD NOT be published.”
  4. Enable DKIM signing at every sending service. Use that service’s instructions to identify the signing domain, selector and public-key DNS value. Publish the matching key and verify that the service is signing with the corresponding private key. The RFC defines how verification works, but does not determine the implementation-specific selector or DNS value for a particular provider.
  5. Plan DKIM key rotation. When replacing a key, coordinate the DNS change with the service’s signing configuration so recipients can retrieve the public key for messages signed by the active key. If old and new keys overlap during a transition, keep the relevant selector records available for the signatures still in circulation.
  6. Publish a DMARC policy for the Author Domain. Choose the alignment mode and handling preference with an understanding of RFC 9989, the current DMARC standard identified here. Monitor aggregate reports where applicable and use observed legitimate sending paths to inform any move to stricter handling.
  7. Coordinate PTR with the IP owner or host. Ask whoever controls the sending IP to confirm reverse mapping and forward/reverse naming expectations for the server. A domain administrator without control of the IP range may not be able to create or change its PTR record.
  8. Validate actual mail paths after DNS changes. Check DNS answers and inspect message headers from messages sent through each legitimate system. Confirm the SPF identity, DKIM signing domain and selector, and DMARC result for the visible Author Domain; separately confirm reverse DNS for the sending IP.

Why DMARC can fail even when SPF passes

An SPF pass and a DMARC pass answer different questions. SPF may pass for a MAIL FROM domain that is not aligned with the visible Author Domain. In that case, SPF has authenticated its SMTP identity, but it does not satisfy DMARC for the visible domain. DMARC can still pass if DKIM passes and its signing domain aligns. If neither SPF nor DKIM both passes and aligns, DMARC fails.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When troubleshooting, check the authenticated domain and alignment result rather than looking only at a generic SPF pass or fail. Also verify the actual From domain, the message’s SMTP identity, DKIM’s signing domain and selector, and the alignment mode configured for DMARC.

Rank #3
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

What email authentication does—and does not—guarantee

SPF, DKIM and DMARC help a domain express authorization and verify domain-based authentication. DMARC lets a domain owner state a handling preference when validation fails and request reports about domain use. A DMARC pass is not proof that a message is truthful, harmless, or destined for the inbox. Authentication is one part of email operations, not a guarantee of inbox placement or a complete anti-phishing solution.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the two meanings of PTR separate

The PTR record used for reverse DNS belongs to the sending IP’s reverse mapping. SPF’s ptr mechanism is a separate SPF policy feature that performs reverse-DNS-related checks. RFC 7208 discourages publishing that SPF mechanism because it is slow, less reliable, and burdens reverse-DNS infrastructure. Avoiding the SPF mechanism does not mean that a mail server’s operational reverse-DNS PTR is irrelevant; coordinate that record with the IP owner or host.

Rank #4
Forvencer Server Book High Volume, Expandable Waitress Book with 2 Zipper
  • Upgraded Magnetic Closure Pocket and Two Zipper Pockets: Unlike other brands, Forvencer server books are designed with two secure zipper pockets and two expandable magnetic pockets. These allow you to easily store and organize a large number of coins, cash, and receipts.
  • Smart Storage & Quick Lookup: 10 multi-functional compartments. On the right side has a check pad, and on the other has a Money Pocket, Tickets Pocket and Credit Card Slot. Two small clear pockets can store bills, receipts and other items to be viewed. A stitched pen loop to store your favorite pen.
  • Long-Lasting and Easy to Clean: Serving book features high-quality PU leather and heavy-duty stitching. PU is extremely strong with high tensile strength and good resistance to tearing, abrasion and scratching. Waterproof leather makes it simple to wipe down your server book with warm water or non-chlorine sanitizer solution to remove any dirt, soil, grime, or soda residue to keep it clean.
  • Fit Perfectly in your Apron: Our 5" x 9" server book is designed to accommodate regular checks and fit easily in your apron pocket.
  • What You Get: Forvencer server book in strict quality control, our worry-free 1-Year warranty, and friendly customer service.

Which standard defines each part?

  • SPF: RFC 7208 (April 2014) defines SPF evaluation and the single-record and processing-limit rules.
  • DKIM: RFC 6376 (September 2011) defines domain-based message signatures and verification.
  • DMARC: RFC 9989 (2026) is the current DMARC specification identified here and supersedes RFC 7489 and RFC 9091. Older configuration guidance based only on those superseded documents may not reflect the current standard.
  • SMTP and reverse mapping: RFC 5321 (October 2008) provides SMTP context, including the possibility that a dynamically allocated client lacks a reverse mapping.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.