SPF / DKIM / DMARC

Sender authentication is three separate mechanisms: SPF authorizes sending IPs, DKIM signs the message, and DMARC tests alignment between them and the visible From domain. These notes trace real failures — SPF PermError and the 10-lookup limit, DKIM selector and body-hash problems, and the 2026 RFC 9989 changes to DMARC — back to the standard that governs them.

New to this? Start with the pillar guide: SPF, DKIM and DMARC for cold email senders (2026)

← All SnapLeads Lab guides