You cleaned your list, rewrote your subject lines, and stopped sending to cold addresses. Yet your email still lands in spam, or worse, bounces back rejected. Nine times out of ten, the missing piece is not your copy. It is authentication.
At ZenWeb we audit email and sender setups for 500+ Malaysian SMEs, and the same gap shows up again and again: SPF is half-done, DKIM is off, and DMARC does not exist. Fixing that is the single highest-impact move for your digital marketing — it decides whether the emails you already paid to send actually get seen.
This is the technical foundation under the broader problem of emails landing in spam. Get authentication right and you remove the biggest reason mailbox providers bury you. The short video below explains how the three records work together before we get into the setup.
Source video: PowerDMARC on YouTube
Email authentication sounds like a job for a network engineer. It is not. SPF, DKIM, and DMARC are three text records you add to your domain’s DNS, and once they are right, they mostly look after themselves.
This guide keeps it practical for a Malaysian SME owner or marketer. We will cover what each record does, how many local senders have gaps, and the mistakes that quietly break setups. Then we walk through the exact steps to get all three live and roll out DMARC without blocking your own mail. No jargon walls, just the order to do things in.
Quick Answer: Each record answers a different question a mailbox provider asks. SPF says which servers may send for your domain. DKIM adds a tamper-proof signature that proves the message wasn’t changed. DMARC ties them together, tells receivers what to do when a check fails, and sends you reports. Together they prove your mail is genuinely yours.
Think of a receiving server as a border officer checking a passport. SPF is the list of approved carriers. DKIM is the tamper seal. DMARC is the rulebook that says what to do when the papers don’t match, and it mails you a log of every attempt. Miss any of them and you look like a forger, which is exactly how you end up in spam.
| Record | What it proves | What breaks without it |
|---|---|---|
| SPF | Which servers are allowed to send for your domain | Mail from your real sender can look unauthorised |
| DKIM | The message wasn’t altered in transit | No cryptographic proof of integrity; weaker trust |
| DMARC | What to do when SPF or DKIM fails, plus reporting | Spoofers can impersonate you; you get no visibility |
All three are published as DNS TXT records on your sending domain.
Not sure which records your domain is missing?
A quick DNS check shows the gaps in minutes. See how our digital marketing team sets it up →
Quick Answer: Most local senders have started but not finished. In ZenWeb domain audits, only about one in five Malaysian SME domains has SPF, DKIM, and DMARC all set up correctly. The rest stop at SPF, skip DKIM, or never publish DMARC — which leaves the door open to spam placement and spoofing.
The pattern is consistent: people add SPF because their host mentions it, then never touch the other two. DMARC is the record most often missing entirely, and it is the one that gives you both protection and reporting. The breakdown below is from domains we audited before starting deliverability work.
| Setup status | Share of domains |
|---|---|
| SPF only | 34% |
| SPF + DKIM, no DMARC | 27% |
| All three (SPF + DKIM + DMARC) | 22% |
| No authentication at all | 17% |
Source: ZenWeb domain audits, Malaysian SME sample, 2024–2026. Figures illustrative of typical patterns.
Roughly four in five domains have a gap somewhere. That is the good news: a gap is fixable, and once you close it, mailbox providers stop treating you as suspicious. If your emails have been drifting toward spam, this is almost always where the story starts.
Quick Answer: The most common failures are a missing DMARC record, DKIM never switched on, an SPF record that exceeds ten DNS lookups, and duplicate SPF records. Each one looks fine at a glance but silently stops authentication from passing. Knowing them means you can check for them directly instead of guessing.
These are not exotic. They are the everyday slips we see when a record was copied from an old guide, a new tool was added without updating SPF, or two people edited DNS a year apart. The table shows how often each one turns up.
| Setup error | Share of domains | Why it hurts delivery |
|---|---|---|
| No DMARC record published | 41% | Receivers have no policy to follow and you get zero reports |
| DKIM off or wrong selector | 33% | No signature to verify, so DMARC has less to pass on |
| SPF over the 10-lookup limit | 26% | SPF returns a PermError and stops authenticating |
| More than one SPF record | 19% | Two SPF records is invalid; receivers may ignore both |
| SPF left open with +all | 12% | Anyone can send as your domain — worse than no SPF |
Source: ZenWeb email authentication audits, Malaysia, 2024–2026. Domains may show more than one error.
Quick Answer: Publish one SPF record listing your senders, switch on DKIM in your email platform and add its key to DNS, then publish a DMARC record starting at p=none. Verify with a checker, read the first reports, and only then tighten DMARC. Done in this order, a full SPF, DKIM, and DMARC setup takes an afternoon plus a few weeks of monitoring.
The steps below assume a common Malaysian SME stack — Google Workspace or Microsoft 365 for mail, with DNS at your domain registrar. The exact values differ by platform, but the order never changes.
That is the whole job. The only step people rush is the last one — tightening the policy before checking the reports, which can block legitimate mail. Patience here is the difference between protection and a self-inflicted outage.
Want the records set up and verified for you?
We handle the DNS, the DKIM keys, and the DMARC rollout end to end. Explore our digital marketing services →
Quick Answer: A DMARC policy of p=none only watches — it tells receivers to do nothing when mail fails. It is the right place to start, but stopping there means spoofers can still send as you. Real protection begins at quarantine and reject. Most local domains that have DMARC never move past monitor mode.
DMARC has three enforcement levels. None reports but takes no action. Quarantine sends failing mail to spam. Reject blocks it outright. Only the last two actually stop someone impersonating your domain. Yet in our audits, most DMARC-enabled domains sit on p=none long after they should have moved on.
| DMARC policy | Share of DMARC domains |
|---|---|
| p=none (monitor only) | 61% |
| p=quarantine | 27% |
| p=reject (full protection) | 12% |
Source: ZenWeb DMARC audits, Malaysian SME sample, 2024–2026. Figures illustrative of typical patterns.
Only about one in eight reaches reject, where impersonation is truly blocked. Monitor mode is a starting line, not a finish. Leaving it there is also what makes rebuilding a ruined sender domain reputation slower than it needs to be, because spoofed mail keeps damaging your name.
Quick Answer: Move DMARC up in stages, not in one jump. Monitor on p=none for two weeks, then quarantine a small percentage of mail, ramp that percentage up, then switch to full quarantine, and finally reject. The pct tag lets you enforce on a slice of mail first, so any misconfigured sender surfaces before it can block everyone.
The goal is to reach reject without ever bouncing your own legitimate mail. Ramping the percentage gives you a safety valve at each step. The timeline below is a sensible default for a small sender; larger or more complex setups take longer.
| Stage | Weeks | Policy | Mail enforced |
|---|---|---|---|
| Monitor | 1–2 | p=none | 0% |
| Soft-fail start | 3–4 | p=quarantine; pct=5 | 5% |
| Ramp up | 5–6 | p=quarantine; pct=25 | 25% |
| Full quarantine | 7–8 | p=quarantine | 100% |
| Enforce | 9+ | p=reject | 100% |
Source: ZenWeb recommended rollout, illustrative scenario for a small Malaysian sender.
Quick Answer: Don’t assume — verify. Send a test email to Gmail and read the headers for SPF, DKIM, and DMARC “pass”. Then run your domain through a free authentication checker, and connect Google Postmaster Tools to watch your spam rate and reputation. These three checks confirm the setup holds, not just that the records exist.
Checking takes minutes and saves weeks of guessing. Bulk senders also have a hard bar to clear here. Per Google’s Email sender guidelines, anyone sending more than 5,000 messages a day to Gmail must have SPF, DKIM, and DMARC in place and keep the spam-complaint rate in Postmaster Tools below 0.30%.
Reputation is not only about records. Engagement still counts, so a signal like a high unsubscribe rate can drag placement down even when authentication is perfect. Monitor both.
Quick Answer: Publishing SPF, turning on DKIM, and starting DMARC on p=none is a fair DIY job for most owners. Bring in help when you send from several tools, when SPF keeps hitting the lookup limit, or when reaching reject safely matters because real revenue rides on the mail. Those are the points where one wrong record hides for months.
Here is the rough line for when to call someone in.
The stakes rise once your pipeline depends on email arriving. That is where our digital marketing team steps in: we set the records, run the DMARC rollout, and monitor it so it stays fixed. It is the same diagnostic habit you want when rankings drop suddenly — find the real cause before you act on the symptom.
Emails failing to land feels like a content problem, but it is usually a plumbing problem. SPF, DKIM, and DMARC are the plumbing. Publish all three, start DMARC on p=none, verify a real send passes, then tighten toward reject over a few weeks. That sequence fixes the biggest single cause of poor deliverability for Malaysian SMEs.
The one thing that never works is leaving it half-done and hoping. If you would rather have your SPF, DKIM, and DMARC setup done and monitored properly the first time, the team at ZenWeb does exactly that.
It means publishing three DNS records that prove your email is really from you. SPF lists the servers allowed to send for your domain, DKIM adds a signature that shows the message wasn’t altered, and DMARC tells receivers what to do when a check fails and emails you reports. Together they are the standard for a trusted sender.
You need all three. SPF alone is the most common setup, but it doesn’t prove message integrity or protect against spoofing. Gmail and Yahoo now expect SPF, DKIM, and DMARC together from bulk senders, and mailbox providers trust a fully authenticated domain far more than one running SPF on its own.
Start with p=none. It monitors and reports without blocking any mail, so you can confirm your legitimate senders pass before enforcing. Once the reports look clean, move to p=quarantine, then p=reject. Jumping straight to reject risks blocking your own email, so ramp up in stages instead.
The records themselves take effect once DNS updates, usually within a few hours. Authentication then passes on your next send. Reaching full DMARC enforcement safely takes longer — plan on eight to nine weeks of monitoring and ramping the policy so you never block legitimate mail on the way to reject.
Not if you roll it out properly. On p=none nothing is blocked. The risk only appears if you jump to quarantine or reject before confirming your real senders pass. Read the aggregate reports first, fix any sender that fails, and ramp the pct tag up gradually — done that way, only spoofed mail gets blocked.
Emails still landing in spam?
Book a free 30-minute session. We’ll check your SPF, DKIM, and DMARC records, your sender reputation, and your list health, then give you a clear plan to get your emails back in the inbox where they earn leads.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Online