DomainCanary Start free

Guides

Last updated 28 Sep 2026

DMARC setup, start to finish Every step from no record to p=reject, with the numbers I use to decide when each step is safe and what to do when a sender will not align. Move to p=reject without losing mail Six checks to run against your reports before you tighten DMARC, the one-word change for each step, and how to move back fast when a step catches real mail. How to read a DMARC aggregate report Open the XML, find the sources that matter, and tell forwarding apart from a misconfigured vendor. A field-by-field walkthrough of a real report. SPF's 10-lookup limit and how to get under it Why SPF caps DNS lookups at ten, what each mechanism costs, and the four ways to get back under the limit ranked by how much maintenance they leave you. DMARC alignment, explained Three domains are involved in every message and DMARC only cares that two match. Relaxed against strict, and why forwarding breaks SPF. What is DMARC What a DMARC record is, why you publish it at p=none first, and how p=reject stops forged mail that uses your exact domain. SPF record syntax, term by term Every SPF record term checked against RFC 7208: qualifiers, mechanisms, modifiers and macros, each with a valid example record and the lookup it costs. Why a domain can only have one SPF record Two v=spf1 records on the same name is a permerror, and permerror fails every sender in both. How to tell if you have two, and how to merge them into one. How many includes one SPF record can hold Nothing caps how many include: terms an SPF record holds. The 10 DNS lookups they spend between them is the cap, and your record does not show that number. Hard bounce vs soft bounce: what each one is telling you A hard bounce is a 5xx refusal, a soft bounce is a 4xx retry. Which codes mean the address is gone, which mean your authentication is broken, and how to tell. How to check your domain reputation, receiver by receiver There is no single domain reputation score. Gmail, Microsoft and the blocklists each keep their own. How to check each one, starting with Postmaster Tools. Spamhaus delisting: find the list, fix the cause, ask once Spamhaus runs five lists and each has its own removal path. Read the return code to see which one has you, fix the cause, then request removal once. Barracuda delisting: check the IP, fix the cause, file once Barracuda lists IPs, not domains, from spam traps and its own appliances. How to check the list, what the form asks, and why a second request is ignored. SPF, DKIM and DMARC: three records, one decision SPF lists your servers, DKIM signs your mail, and DMARC is the only one that tells a receiver what to do. How the three fit, and where alignment comes in. Email spoofing: how a forged From works, and what stops it The From address on an email is text the sender types. How spoofing works, why the reader can't tell, what DMARC at p=reject stops, and what it doesn't. DKIM fail: find the cause before you change DNS Fix DKIM failures using the email's headers. Check signing, selectors, DNS keys and changed messages, even when a DKIM checker says the record is valid. NCSC Mail Check is retired: move your DMARC reports Mail Check stopped DMARC reporting in March 2025 and closed in March 2026. Check your rua address, choose a free report reader and change that tag only. Direct Send spoofing: block it in Microsoft 365, then fix DMARC Attackers use Direct Send to mail Microsoft 365 users as their own domain. Turn on Reject Direct Send, add connectors, and move DMARC off p=none. Emails going to spam: find the cause, receiver by receiver Why your emails go to spam at Gmail, Outlook and Yahoo even when SPF, DKIM and DMARC pass. Check complaints, consent, reputation and content, in that order. SPF softfail: what it means, and when to change ~all spf=softfail means the sending server isn't in your SPF record and the record ends in ~all. What receivers do with it, what DMARC does, and which fix applies.

Elsewhere on the site

Or check a domain right now with the free DMARC, SPF and DKIM lookups.

What these guides depend on

Every policy step in these guides depends on reading the aggregate reports. We parse them and mail you a weekly summary. Paid plans email you the day a new source first fails. The first domain is free.

Get the weekly digest

Free for your first domain · No card · Per-source totals kept for life