Guides
Last updated 2026-08-28
DMARC setup, start to finish
The full ramp from no record to p=reject, with the numbers I use to decide when each step is safe and what to do when a sender will not align.
How to read a DMARC aggregate report
Open the XML, find the sources that matter, and tell forwarding apart from a misconfigured vendor. A field-by-field walkthrough of a real report.
SPF's 10-lookup limit and how to get under it
Why SPF caps DNS lookups at ten, what each mechanism costs, and the four ways to get back under the limit ranked by how much maintenance they leave you.
DMARC alignment, explained
Three domains are involved in every message and DMARC only cares that two match. Relaxed against strict, and why forwarding breaks SPF.
What is DMARC
What a DMARC record is, why you publish it at p=none first, and how p=reject stops forged mail that uses your exact domain.
SPF record syntax, term by term
Every SPF record term checked against RFC 7208: qualifiers, mechanisms, modifiers and macros, each with a valid example record and the lookup it costs.
Elsewhere on the site
Bounce and error codes
The literal string from your log, and what to change.
SPF and DKIM by provider
The records each platform needs, and where alignment breaks.
Or check a domain right now with the free DMARC, SPF and DKIM lookups.
What these guides depend on
Every ramp in these guides depends on reading the aggregate reports. We parse them and mail you a weekly summary. Paid plans email you the day a new source first fails. The first domain is free.
Get the weekly digestNo card · 12+ months of history · The free plan does not expire