SPF
Lists the servers allowed to send mail as your domain. Ending in -all tells receivers to distrust everything else.
GUIDES / TRUST
SPF, DKIM and DMARC decide one narrow, important thing: whether a stranger can send email that claims to be from your domain — and whether the world's mail servers have been told to refuse it. This guide explains what each record does, and is honest about the limits.
Check Your Digital Readiness01 / THE RECORDS
Lists the servers allowed to send mail as your domain. Ending in -all tells receivers to distrust everything else.
Signs your outgoing mail so tampering and forgery are detectable by the receiver.
Tells receiving servers what to do with mail that fails the checks — and p=reject is the setting that actually refuses forgeries.
Says where your incoming mail is delivered, and reveals which provider runs it.
02 / WHY IT MATTERS HERE
Over one hundred Kenyan parastatal chief executives were put on notice over exactly these records — the full story is in Insights. A domain without them can be impersonated to its own customers, suppliers and bank; most recipients will never spot the difference.
03 / THE HONEST LIMITS
YOUR NEXT STEP
Identify the priorities, understand the responsibility and then continue through the route that fits the work.