The longer version
How email changed
Twenty years of email worked one way. In fifteen months it started working another way. Here's what happened, what the four records do, and why the change is invisible from your own inbox.
The old deal: authentication was a hint
For most of email's life, a receiving server took everything it knew about a message — the words, the links, the sending server's history, whether the recipient had ever replied to you — and produced a score. Authentication records were one input among many. A well-behaved business with a badly configured domain still got through, because everything else about the message looked fine.
That tolerance is what let small businesses ignore this for two decades. Your web developer set up a mail record in 2011, you added a newsletter tool in 2016, you moved to Microsoft 365 in 2020, and none of it broke loudly enough to notice.
February 2024: Google and Yahoo set a floor
From 1 February 2024, Google published requirements every sender to Gmail must meet: SPF or DKIM authentication on your sending domain, valid forward and reverse DNS on your sending server, TLS for the connection itself, messages formatted to the RFC 5322 standard, and a spam complaint rate kept under 0.3%. Yahoo announced a matching set within days of Google.
Send more than 5,000 messages a day and the bar goes higher: SPF and DKIM and a DMARC record, with the domain in your visible From: address aligned to one of them, plus one-click unsubscribe on marketing mail.
Most small businesses read the words “bulk sender” and concluded none of it applied. The baseline requirements applied to them from day one.
Google's sender guidelines ↗May 2025: Microsoft stopped delivering
On 5 May 2025, Microsoft began enforcing its own requirements for domains sending more than 5,000 messages a day to Outlook.com, Hotmail.com and Live.com. SPF, DKIM and DMARC — with DMARC at p=none as the bare minimum and alignment on at least one of SPF or DKIM.
Non-compliant mail went to the Junk folder first. Then it stopped arriving at all, bounced with a message reading 550 5.7.515 Access denied, sending domain does not meet the required authentication level. That's a hard bounce. No delivery, no second chance, no “check your junk folder”.
Two providers, one direction of travel. Authentication moved from being a signal that influenced a spam score to being a condition of entry checked before anything else.
The four records, in plain English
SPF
A list of who's allowed to send as you
A public list of the servers and services permitted to send email using your domain name. Your mail host, your accounting software, your newsletter platform. Anything not on the list is unauthorised. It has one notorious limit: the record may trigger at most ten DNS lookups, and each service you add uses at least one. Exceed ten and the whole record is thrown out — not just the last entry. Silently.
DKIM
A signature that proves the message wasn't tampered with
Your mail server signs each outgoing message with a private key; the matching public key sits in your DNS, under a name called a selector. The receiver checks the signature. Unlike SPF, DKIM survives forwarding — which is why it matters more than most people realise. Every service that sends as you needs its own key installed.
DMARC
The instructions for what to do when the first two fail
It ties SPF and DKIM to the domain your customer actually sees in the From: line, and tells receivers what to do about failures: nothing (p=none), send to junk (p=quarantine), or refuse outright (p=reject). It also asks receivers to email you daily reports about mail sent in your name. Most domains that have DMARC have it set to none, which stops nothing at all — the correct first step that nobody takes a second step from.
MX
Where your incoming mail goes
The least glamorous of the four and the easiest to leave stale after a migration. Old records pointing at a web host you no longer pay for are a common finding, and a genuine security problem — mail can end up somewhere you don't control.
Why you can't see any of this yourself
Test emails to your own address always arrive — same domain, trivially trusted. Emails to your bookkeeper always arrive; they have you in their contacts and have replied to you a hundred times. Personal history overrides almost everything.
The mail that fails is the mail to someone who has never heard from you: the new client, the prospect who filled in your form, the supplier you're quoting for the first time. Exactly the mail whose non-arrival looks identical to disinterest. Nobody emails to say “your invoice went to my junk folder”. They just don't reply.
And the failures aren't all-or-nothing. One tool of the six you send from is unauthorised, so your appointment reminders fail while your quotes are fine. Or a forwarded address breaks alignment, so the same message that reached one client bounces at another.
Find out where you actually stand.
The free checker on the home page reads your records in a few seconds. The paid review works out whether they cover everything you send.