
Grace Adeyemi
My whole beat is three records answering the same question from different directions: who may send mail as this domain. SPF looks at the DNS record and the connecting host. DKIM signs the message and carries the signature in a header. DMARC ties a visible From address to a policy and tells receiving servers what to do when the two disagree. Hold that shape and the failures stop being mysterious. SPF has a hard limit of ten DNS lookups, and includes, redirects and MX entries all count against it. People build a record that works in testing and breaks when the tenth mechanism resolves. The qualifier on the all mechanism matters most: fail, softfail, neutral and pass each mean something different, and a default of neutral weakens the record without looking weakened. DKIM depends on a keypair, with the public half published as a DNSKEY at a chosen selector. Selector rotation exists because a signing key cannot safely be replaced without overlap, and because a leaked key should stop being trusted quickly. Signature canonicalization lets a mail system rewrite headers and lines without breaking the signature. Alignment is what people get wrong: relaxed alignment matches the organisational domain, strict alignment matches the exact domain, and DMARC uses strict alignment for the visible From address. DMARC carries a policy of none, quarantine or reject, plus a percentage for staged rollout. The rua address collects reports, and those reports are the fastest way to find legitimate senders nobody authorised yet. I keep the boundary in view too. Authoritative nameservers, zone transfers and CAA records decide who can speak for a domain at all, and that sits underneath all three mail records.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →