Magnetly
    Conversion strategy

    SPF, DKIM and DMARC: The Email Authentication Guide 80% of Companies Get Wrong

    Around 80% of domains still have no DMARC record or a policy that protects nothing. Here is what SPF, DKIM and DMARC actually do, and how to fix yours in an afternoon.

    Victor CHARLE

    Victor CHARLE

    AI Lead Magnet Strategy

    7 min readUpdated Jun 18, 2026

    If your emails land in spam, your domain authentication is usually the reason. And you are far from alone: studies of large domain samples in 2026 find that roughly 80% of domains either have no DMARC record at all or run a policy that protects nothing. SPF adoption sits around 56%, DMARC around 30%, DKIM around 23%, depending on the dataset. Most companies think they are covered. Very few actually are.

    This guide explains what SPF, DKIM and DMARC really do, the mistakes that quietly break them, and how to get to a protected domain without a consultant. No jargon for the sake of jargon.

    Why this suddenly matters more

    Email authentication used to be a best practice you could postpone. That window closed. Google and Yahoo introduced bulk sender requirements for anyone sending more than 5,000 messages a day, and Microsoft followed with its own enforcement for Outlook.com. The important shift is what happens when you fail: reports through 2026 describe permanent SMTP rejections rather than a quiet trip to the spam folder. Industry analyses put compliant senders around 89% inbox placement, while non-compliant senders see a large share of mail filtered or refused outright.

    Two consequences. If you send any volume of marketing or transactional email, authentication is now the price of entry. And even if you send very little, an unprotected domain is trivially easy for anyone to spoof in your name.

    SPF: who is allowed to send for you

    SPF (Sender Policy Framework) is a DNS record listing the servers permitted to send email using your domain. The receiving server looks up your SPF record and checks whether the sending IP is on the list.

    The trap nobody mentions: SPF has a hard limit of 10 DNS lookups. Every service you add (your mail provider, your CRM, your invoicing tool, your newsletter platform) consumes lookups, and once you cross 10 the record returns a PermError and effectively stops working. This is extremely common. One audit of heavily scrutinized government domains found around 60% had SPF errors, including records that blew past the lookup limit.

    What to do: keep one SPF record per domain (never two), list only services you actually send from, remove old tools, and flatten or consolidate includes if you are near the limit.

    DKIM: proof the message was not tampered with

    DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing messages. Your provider signs with a private key, publishes the public key in your DNS, and the receiver verifies the signature. If it checks out, the message genuinely came from your domain and was not altered in transit.

    The common failure here is partial coverage: DKIM is enabled on the main mail platform but not on the other tools that send in your name, so a portion of your mail fails silently. Every sending service needs its own DKIM key published.

    DMARC: the policy that ties it together

    DMARC (Domain-based Message Authentication, Reporting and Conformance) is where most companies stop too early. It does two things: it tells receivers what to do when SPF and DKIM fail, and it sends you reports on who is sending mail using your domain.

    The policy has three levels. p=none means monitor only, do nothing. p=quarantine sends failing mail to spam. p=reject blocks it outright. Here is the part that explains the 80% figure: a huge share of domains that "have DMARC" are sitting on p=none, which protects nothing at all. It is a listening post, not a lock. Analyses in 2026 estimate only around 11% of domains reach full protection at p=reject.

    The other half of DMARC is alignment, and it is the subtlety that catches people out. Passing SPF or DKIM is not enough on its own: the domain that passes must also match the domain your recipients see in the From field. Plenty of setups pass SPF technically while failing alignment, which means failing DMARC.

    The five mistakes that break authentication

    Running two SPF records on the same domain, which invalidates both. Exceeding the 10 DNS lookup limit and returning PermError. Enabling DKIM on one platform but not on the other tools that send for you. Leaving DMARC on p=none for years and assuming that counts as protection. And never reading the DMARC reports, which is where you would have spotted the unauthorized sender or the misconfigured tool.

    How to fix it, step by step

    Start by inventorying every service that sends email in your name: mail provider, CRM, support desk, invoicing, marketing platform, form notifications. You cannot authenticate what you have not listed.

    Publish a single SPF record covering exactly those services, and check you are under the 10 lookup limit. Then enable DKIM on every one of them individually, publishing each public key in DNS.

    Next, publish DMARC at p=none with a reporting address. This is deliberately the safe starting point: you collect data without risking legitimate mail. Read those reports for two to four weeks and fix whatever fails alignment.

    Then move to p=quarantine, ideally with a percentage rollout, and watch again. Once your reports are clean, go to p=reject. That final step is the one 80% of companies never take, and it is the only one that actually stops spoofing.

    Finally, keep it maintained. Every new tool you connect can break alignment, so re-check when your stack changes.

    Turn this into a lead magnet (the smart play)

    Here is the marketing angle if you sell to businesses. Authentication is a problem almost every company has, cannot easily self-diagnose, and feels anxious about. That is the perfect profile for an interactive lead magnet.

    A free "email deliverability checker" or "domain authentication scorecard" is exactly the kind of tool that converts: the visitor enters a few details about their setup, gets an instant score plus the specific gaps to fix, and hands over an email to see the full report. It qualifies the lead (you learn their stack and their maturity) and it opens the sales conversation with a real problem rather than a pitch. This is the same mechanic behind the graders that generate enormous inbound volume, which we break down in the psychology of high-converting lead magnets and interactive forms for lead generation.

    How to build your own lead magnet with Magnetly (step by step)

    Step 1: Create your free account. Head to Magnetly and sign up. No code, no credit card.

    Step 2: Drop in your website. In the lead magnet generator, pick the "from your website" option and paste your site link. The AI reads your site and drafts a full interactive lead magnet, questions, logic, and result, tailored to your business.

    Step 3: Make it yours. Tweak the visuals so it matches your brand. Stuck on the design? Book a quick call with our CEO and we will fix it with you.

    Step 4: Preview and stress-test it. Hit "Preview" and run through it yourself. Make sure the final result is sharp and genuinely useful. If the ending is not landing, book a call and we will tune it together.

    Step 5: Publish and embed it. Publish your checker, then embed it on your site where your traffic already lands. Stuck embedding? Grab a call and we will walk you through it.

    Step 6: Turn leads into revenue. Once it is live and collecting leads, enrich those contacts and reach out based on their score. That is where a checker turns into booked calls.

    Need ideas fast? Use our free lead magnet idea generator to get quiz, calculator, assessment, simulator, and diagnostic ideas tailored to your business in seconds.

    Fix your own authentication first, then build the checker that finds everyone else's gaps. Try the Magnetly lead magnet generator and have it live this week.

    Related reads: Lead magnet examples, the best lead magnet for SaaS, and the best lead magnet for web and design agencies.

    Sources: Google, Yahoo and Microsoft bulk sender requirements (5,000+ messages per day, SPF, DKIM and DMARC required); 2026 DMARC adoption studies reporting roughly 80% of domains with no DMARC record or a non-enforcing policy, SPF adoption around 56%, DMARC around 30%, DKIM around 23%, and approximately 11% of domains at full p=reject enforcement; government domain audit finding around 60% with SPF errors including breaches of the 10 DNS lookup limit; industry deliverability analyses reporting around 89% inbox placement for compliant senders versus a large share filtered or rejected for non-compliant senders. Figures vary by dataset and methodology.

    Related reads

    Magnetly · 30 min

    Strategy call

    Available slots

    10:0011:3014:0015:3017:00+more

    Example availability — pick a real slot on the calendar.

    Louis · Magnetly team
    Free strategy call

    Want a human eye on your lead magnet strategy?

    If you made it this far, you probably have a tool idea worth testing. Book a free call and we’ll help you choose the right magnet, placement and conversion angle for your traffic.

    • Free strategy call
    • No pressure
    • Actionable advice
    Book a free strategy call
    or

    Let AI create your magnet for free

    Paste your website URL and Magnetly will generate a branded lead magnet you can embed or share.

    No credit card required Lead magnet generated in 3 minutes Uses your site’s branding automatically

    Generated from your website URL.