4 ms·
spf : the receiving server can check (in a public dns record) which server is allowed to send for this domain dkim : the email is signed (using a private key)
by peppermint_tea 5y ago
spf : the receiving server can check (in a public dns record) which server is allowed to send for this domain
dkim : the email is signed (using a private key) with a unique signature, the receiving server can validate the DKIM signature by running a DNS query to search for the public key for that domain .
dmarc : publish a policy on how emails that does not satisfy the above condition above (spf & dkim) should be handled (quarantine, reject) and optionally sends you a report on who send/tried to send emails on the behalf of your domain
Edit : I misread your question... it is odd indeed that only satisfying one condition is enough for a pass...
- _blu 5y agowhat is the consequence if i set my dmarc to reject? i'm afraid
- escalt 5y agoThen E-Mails which fail the SPF and DKIM checks should be rejected by the receiving server. Many mailservers still let them through though because they just don't check dmarc or put them in a spam folder or quarantine.
- pracer 5y agoI would add that SPF alone may not be enough, and that's why some of the other mechanisms are needed. AFAIK if you have a softfail SPF (a record ending in `~`), you would need DMARC or DKIM. But the SPF is needed always in order to specify the domains/ip that are allowed. The other two mechanisms are used for making it more strong and reducing the potential phishing attacks. In particular, a softfail SPF may be fixed by using a "rejected" or "quarantine" DMARC policy. But this is from the RFC document, so it may be that in practical cases things are more nuanced.