Clear, practical instructions for authenticating a sending domain with SPF, DKIM, and DMARC and why each matters for deliverability. SPF lists which sending IPs are allowed and is checked against the envelope sender (Return-Path), so forwarding often breaks SPF; DKIM adds a cryptographic signature whose public key lives in a DNS record under _domainkey and proves message integrity; DMARC ties SPF/DKIM results to the visible From address, requires alignment (relaxed or strict), and lets receivers apply a policy (none, quarantine, reject) and send reports. Misunderstanding which domain each check looks at is the common cause of failures: SPF/DKIM can pass for unrelated domains while DMARC fails.
Concrete setup advice and implementation caveats focus on using a dedicated sending subdomain (e.g., mail.example.com) and on correct DNS records. Publish DKIM selectors (Mailfully uses CNAMEs to host keys for rotation), set DKIM CNAMEs to DNS-only on Cloudflare, and verify with dig. Configure a custom MAIL FROM (send.mail.example.com) with MX and SPF TXT so SPF can align, remembering one SPF record per name and the 10-lookup limit. Watch DNS host forms to avoid appending the zone twice. Test both that records are published and that actual messages pass authentication.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.