SHEET 03 / AUTH
Three records, three different jobs.
SPF authorises sending paths, DKIM signs messages and DMARC connects visible identity to those checks while defining reporting and policy.
01
SPF controls sending paths
Publish one SPF record and include only active services. Recursive DNS lookups count toward the protocol limit.
02
DKIM signs each message
The sender holds the private key; DNS publishes the public key at a selector under _domainkey.
03
DMARC checks alignment
Start with reporting, read the reports and move to a stricter policy only after legitimate senders pass consistently.