LearnlystLearnlyst
DMARC for a Small Domain
Tech & Internet

DMARC for a Small Domain

SPF, DKIM, then p=none — so nobody else can send as you

1h 15m7 photographed stepsIntermediate

You will publish SPF, turn on DKIM at your email host, add a DMARC record that starts at p=none, read a week of reports, then tighten to quarantine. This is for a domain you own (a shop, a newsletter, a one-person company). It stops spoofed invoices in your name. It is not a hacking class.

What you'll learn

  • SPF is a list of who may send — one record, includes not a novel
  • DKIM is a signature the mailbox checks
  • DMARC starts at p=none so you do not break real mail
  • How to move to quarantine after reports look clean

Inside this course

  • What you are actually publishingThree TXT records. Wrong quotes and extra spaces are how this fails.
  • DKIM at the host, not in a blog commentThe mail host gives you a hostname and a public key. You paste it into DNS. You do not invent the key.
  • DMARC starts as a camera, not a hammerp=none means: still deliver, but send me reports. That is the whole first week.
  • Tighten once, then leave itQuarantine is the grown-up setting for a small shop. Reject is for when you know the inventory is complete.

Full step-by-step lessons with photos unlock with a subscription.

DMARC for a Small Domain preview 1
DMARC for a Small Domain preview 2
DMARC for a Small Domain preview 3

Free preview

First steps from What you are actually publishing

See how every step looks — photo, checklist, and pro tips included.

One column: tool. One column: sends as your domain? Yes/no.
01List every box that sends as @yourdomain

Write them down: Google Workspace or Microsoft 365, the website contact form, the billing tool (Stripe receipts often send from stripe.com — that is fine), the newsletter ESP, a support desk. If a tool sends as you@yourdomain, it needs to be in SPF and usually DKIM.

If you miss the ESP, DMARC later will make those campaigns bounce and you will blame DMARC instead of your own list.

One SPF record — includes, not a pile of duplicates
02One SPF record — includes, not a pile of duplicates

SPF is a single TXT on the root (or the mail hostname): v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all — yours will match YOUR hosts, not this example pasted blindly.

Two SPF records on the same name = fail. Merge with include: and ip4: only if you know the IP. End with ~all (soft fail) until DMARC is proven. -all comes later. Lookup limits: too many includes flatten into a permerror. Keep it short.

Full library access

Unlock every course

Subscribe for $9/month or $79/year — every category, every guide.

View plans

Free tips from this course

Each tip has its own step photo — browse free, then unlock the full course.

More Tech & Internet tips →

More in Tech & Internet

Related courses with photographed steps — browse before you subscribe.

Unlock DMARC for a Small Domain + the full library

$9/month · Cancel anytime · All courses included

Sign up to unlock