E-Mail-Authentifizierung & DMARC7 min read2 sections

Practical Setup Guide

Step-by-step guide to implementing DMARC: from zero to full enforcement, including third-party sender configuration.

01

Step-by-Step DMARC Implementation

Step 1: Audit Your Email Senders

Before touching DNS, make a list of every service and server that sends email using your domain:

  • Your own mail server(s)
  • Email service provider (Google Workspace, Microsoft 365, etc.)
  • Marketing tools (Mailchimp, HubSpot, etc.)
  • Transactional email (SendGrid, Amazon SES, Postmark, etc.)
  • CRM/Support (Salesforce, Zendesk, Freshdesk, etc.)
  • Billing/Invoicing systems
  • Web application (password resets, notifications)

Step 2: Configure SPF

Create an SPF record that includes all authorized senders:

v=spf1 include:_spf.google.com include:sendgrid.net include:servers.mcsv.net ip4:198.51.100.10 ~all

Use ~all (Soft Fail) initially. Switch to -all (Hard Fail) after monitoring.

Step 3: Configure DKIM

Set up DKIM signing for each service. Each service will provide a DNS record to publish. Verify each signature is valid using a DKIM checker.

Step 4: Publish DMARC in Monitoring Mode

_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:your-rua@dmarc.provider.tools; ruf=mailto:your-ruf@dmarc.provider.tools; fo=1"

Step 5: Monitor Reports for 2-4 Weeks

Use Provider.tools to analyze incoming Aggregate Reports. Look for:

  • Legitimate senders that are failing authentication (fix their SPF/DKIM)
  • Unknown senders (investigate — legitimate or Spoofing?)
  • High fail rates from specific IPs

Step 6: Move to Quarantine (Gradual)

v=DMARC1; p=quarantine; pct=10; rua=mailto:rua@dmarc.provider.tools

Monitor for a week, then increase pct to 25%, 50%, 75%, 100%.

Step 7: Move to Reject

v=DMARC1; p=reject; rua=mailto:rua@dmarc.provider.tools; adkim=s; aspf=s

Same gradual pct increase. Congratulations — your domain is now fully protected!

02

Handling Third-Party Senders

Third-party email services are the #1 source of DMARC Alignment failures. Here's how to configure the most common ones:

Google Workspace

  • SPF: include:_spf.google.com
  • DKIM: Generate in Admin Console → Apps → Google Workspace → Gmail → Authenticate email
  • Alignment: Automatic when DKIM is configured with your domain

Microsoft 365

  • SPF: include:spf.protection.outlook.com
  • DKIM: Enable in Microsoft 365 Defender → Email authentication → DKIM
  • Alignment: Publish CNAME records for selector1 and selector2

Amazon SES

  • SPF: include:amazonses.com or use a custom MAIL FROM domain
  • DKIM: Enable Easy DKIM in SES → Verified identities → Your domain
  • Custom MAIL FROM: Critical for SPF Alignment — set to mail.yourdomain.com

SendGrid

  • SPF: include:sendgrid.net
  • DKIM: Domain Authentication in Settings → Sender Authentication
  • Branded Links: Use a subdomain like email.yourdomain.com

Mailchimp

  • SPF: include:servers.mcsv.net
  • DKIM: Authenticate domain in Account → Domains
Pro Tip: For services that cannot align with your main domain, use a dedicated subdomain (e.g., marketing.example.com) with its own SPF, DKIM, and DMARC records.