Short answer: SPF, DKIM and DMARC are three DNS records that prove an email really comes from your domain. SPF lists the servers allowed to send for you, DKIM adds a digital signature that shows the email wasn't changed, and DMARC tells inbox providers what to do if a message fails those checks. Without them, Gmail, Yahoo and Outlook are likely to send your email to spam or reject it.
Why these records exist
Email was designed in the 1970s with no way to check who sent a message. Anyone could put "yourbank.com" in the From line. Phishing and fraud, which many Nigerians see every day in their inbox, rely on that. SPF, DKIM and DMARC were added on top so receiving servers can check whether an email claiming to be from your domain is genuine. Today the big providers treat unauthenticated email as suspicious by default.
SPF: the list of who may send
SPF (Sender Policy Framework) is a single TXT record on your domain listing the services allowed to send email for it. When Gmail receives an email from you, it checks whether the sending server is on that list.
A typical SPF record looks like this:
v=spf1 include:_spf.google.com include:amazonses.com ~all
That says: Google Workspace and Amazon SES may send for this domain; treat anything else as suspicious. Two common mistakes: having two SPF records (you must merge them into one), and listing so many services that the record needs more than 10 lookups.
DKIM: the tamper-proof signature
DKIM (DomainKeys Identified Mail) signs each outgoing email with a private key held by your email service. The matching public key is published in your DNS, usually as one or more CNAME or TXT records with names like selector._domainkey.yourbusiness.com. The receiving server uses it to confirm the email came from your domain and wasn't changed on the way. Each service you send through has its own DKIM records.
DMARC: the policy and the reports
DMARC ties SPF and DKIM to the domain people actually see in the From line, and tells receivers what to do when an email fails: nothing (p=none), put it in spam (p=quarantine), or reject it (p=reject). It also asks receivers to send you reports about who is sending as your domain.
A safe starting record, added as a TXT record named _dmarc.yourbusiness.com:
v=DMARC1; p=none; rua=mailto:dmarc@yourbusiness.com
Start with p=none to collect reports for a few weeks. Once all your real email (office mail, invoices, marketing) passes, move to p=quarantine, then p=reject. That stops fraudsters sending as your domain.
BIMI: your logo in the inbox
BIMI (Brand Indicators for Message Identification) shows your logo next to your emails in Gmail, Yahoo and Apple Mail. It needs DMARC at quarantine or reject, your logo as a special SVG file, and for Gmail a paid certificate (a VMC or CMC). It's a nice trust signal once the basics are solid. ENB checks your logo file and DMARC policy for you.
Do you need your own domain?
No. If you don't have one, ENB sends your campaigns from its own domain, which already has SPF, DKIM and DMARC, with your business name as the sender and Reply-To set to your Gmail. You get good deliverability from day one. When you are ready, a domain costs a few thousand naira a year and makes every email look more professional.
How to set it up with your own domain
- Find where your domain's DNS is managed: often Cloudflare, Namecheap, Whogohost, or your web host.
- In ENB, add your domain under sending domains. The app shows the exact records to copy.
- Add the DKIM records and the custom MAIL FROM records (for SPF alignment) in your DNS.
- Add or update your DMARC record, starting at
p=none. - Click verify in ENB. DNS changes usually show within minutes, sometimes a few hours.
If you also send office email through Google Workspace or Microsoft 365, keep their SPF entry and DKIM too: every service that sends as your domain must be authenticated.
Quick reference
| Record | Type | What it does |
|---|---|---|
| SPF | TXT on yourbusiness.com | Lists who may send |
| DKIM | CNAME or TXT on selector._domainkey | Signs each email |
| DMARC | TXT on _dmarc | Sets the policy and reports |
| BIMI | TXT on default._bimi | Points to your logo |
Common problems and how to fix them
- "SPF permerror" or "too many DNS lookups": your SPF record includes too many services. Remove services you no longer use, and merge everything into one record.
- DKIM fails after moving your website: some web hosts replace your DNS when you move. Check the DKIM records are still there after any hosting or DNS change.
- DMARC fails although SPF passes: SPF passed for the bounce domain, not your From domain. Set up a custom MAIL FROM (ENB shows the records) or make sure DKIM is signed with your domain.
- Office email lands in spam after you move to p=reject: a service you forgot (a website contact form, an accounting tool, a printer that emails scans) isn't authenticated. Read your DMARC reports before tightening the policy.
- Records added but still "pending": DNS can take a few hours to update. Check you added the record on the right name (some DNS panels add your domain automatically, so "selector._domainkey.yourbusiness.com.yourbusiness.com" is a common slip).
How to check your records
Send an email to a Gmail address you own, open it, choose "Show original", and look for "SPF: PASS", "DKIM: PASS" and "DMARC: PASS". ENB's spam check shows the same three results for every campaign before you send.
Frequently asked questions
Do I need SPF, DKIM and DMARC?
Yes if you send from your own domain. Gmail and Yahoo require all three for bulk senders, and they make every email more likely to reach the inbox.
Where do I add these records?
In the DNS settings of your domain, at the company that manages it (for example Cloudflare, Namecheap or your web host).
What DMARC policy should I start with?
Start with p=none to collect reports, then move to quarantine and reject once all your legitimate email passes.
Can I have two SPF records?
No. A domain must have only one SPF record. Merge the include: entries into one.