ZenWeb - Blog - SPF, DKIM, DMARC Not Set Up? Fix Your Sender Reputation

SPF, DKIM, DMARC Not Set Up? Fix Your Sender Reputation

July 28, 2026

Share this post:

SPF, DKIM, DMARC Not Set Up? Fix Your Sender Reputation
TL;DR: SPF, DKIM, and DMARC are three DNS records that prove an email is really from you. Without them, Gmail and Yahoo treat you as unverified and your mail slides into spam or gets rejected. Publish all three, start DMARC on p=none, then tighten to reject. For most Malaysian SMEs, a correct SPF DKIM DMARC setup lifts inbox placement within a few weeks.

You cleaned your list, rewrote your subject lines, and stopped sending to cold addresses. Yet your email still lands in spam, or worse, bounces back rejected. Nine times out of ten, the missing piece is not your copy. It is authentication.

At ZenWeb we audit email and sender setups for 500+ Malaysian SMEs, and the same gap shows up again and again: SPF is half-done, DKIM is off, and DMARC does not exist. Fixing that is the single highest-impact move for your digital marketing — it decides whether the emails you already paid to send actually get seen.

This is the technical foundation under the broader problem of emails landing in spam. Get authentication right and you remove the biggest reason mailbox providers bury you. The short video below explains how the three records work together before we get into the setup.

The Complete Guide to DMARC, SPF & DKIM with PowerDMARC

Source video: PowerDMARC on YouTube


1. Introduction

Email authentication sounds like a job for a network engineer. It is not. SPF, DKIM, and DMARC are three text records you add to your domain’s DNS, and once they are right, they mostly look after themselves.

This guide keeps it practical for a Malaysian SME owner or marketer. We will cover what each record does, how many local senders have gaps, and the mistakes that quietly break setups. Then we walk through the exact steps to get all three live and roll out DMARC without blocking your own mail. No jargon walls, just the order to do things in.


2. What SPF, DKIM, and DMARC Actually Do

Quick Answer: Each record answers a different question a mailbox provider asks. SPF says which servers may send for your domain. DKIM adds a tamper-proof signature that proves the message wasn’t changed. DMARC ties them together, tells receivers what to do when a check fails, and sends you reports. Together they prove your mail is genuinely yours.

Think of a receiving server as a border officer checking a passport. SPF is the list of approved carriers. DKIM is the tamper seal. DMARC is the rulebook that says what to do when the papers don’t match, and it mails you a log of every attempt. Miss any of them and you look like a forger, which is exactly how you end up in spam.

SPF vs DKIM vs DMARC at a Glance
RecordWhat it provesWhat breaks without it
SPFWhich servers are allowed to send for your domainMail from your real sender can look unauthorised
DKIMThe message wasn’t altered in transitNo cryptographic proof of integrity; weaker trust
DMARCWhat to do when SPF or DKIM fails, plus reportingSpoofers can impersonate you; you get no visibility

All three are published as DNS TXT records on your sending domain.

Key takeaway: SPF and DKIM do the checking; DMARC decides what happens when a check fails and reports back. You need all three working together, not one or two.

Not sure which records your domain is missing?

A quick DNS check shows the gaps in minutes. See how our digital marketing team sets it up →


3. How Many Malaysian SMEs Have Authentication Gaps

Quick Answer: Most local senders have started but not finished. In ZenWeb domain audits, only about one in five Malaysian SME domains has SPF, DKIM, and DMARC all set up correctly. The rest stop at SPF, skip DKIM, or never publish DMARC — which leaves the door open to spam placement and spoofing.

The pattern is consistent: people add SPF because their host mentions it, then never touch the other two. DMARC is the record most often missing entirely, and it is the one that gives you both protection and reporting. The breakdown below is from domains we audited before starting deliverability work.

Email Authentication Setup Status — Malaysian SME Domains
Share of audited Malaysian SME domains by email authentication setup status, from ZenWeb audits.
Setup statusShare of domains
SPF only

34%

SPF + DKIM, no DMARC

27%

All three (SPF + DKIM + DMARC)

22%

No authentication at all

17%

Source: ZenWeb domain audits, Malaysian SME sample, 2024–2026. Figures illustrative of typical patterns.

Roughly four in five domains have a gap somewhere. That is the good news: a gap is fixable, and once you close it, mailbox providers stop treating you as suspicious. If your emails have been drifting toward spam, this is almost always where the story starts.

Key takeaway: Only about 22% of local SME domains we audit are fully set up. If you are not sure whether yours is, assume there is a gap and check — the odds say there is one.

4. The Setup Mistakes That Quietly Break Authentication

Quick Answer: The most common failures are a missing DMARC record, DKIM never switched on, an SPF record that exceeds ten DNS lookups, and duplicate SPF records. Each one looks fine at a glance but silently stops authentication from passing. Knowing them means you can check for them directly instead of guessing.

These are not exotic. They are the everyday slips we see when a record was copied from an old guide, a new tool was added without updating SPF, or two people edited DNS a year apart. The table shows how often each one turns up.

Most Common Email Authentication Setup Errors
Most common SPF, DKIM, and DMARC setup errors and why they hurt delivery, from ZenWeb audits in Malaysia.
Setup errorShare of domainsWhy it hurts delivery
No DMARC record published41%Receivers have no policy to follow and you get zero reports
DKIM off or wrong selector33%No signature to verify, so DMARC has less to pass on
SPF over the 10-lookup limit26%SPF returns a PermError and stops authenticating
More than one SPF record19%Two SPF records is invalid; receivers may ignore both
SPF left open with +all12%Anyone can send as your domain — worse than no SPF

Source: ZenWeb email authentication audits, Malaysia, 2024–2026. Domains may show more than one error.

Key takeaway: A record that exists is not the same as a record that works. Check for these five specific faults rather than assuming a published SPF or DKIM line is doing its job.

5. How to Set Up SPF, DKIM, and DMARC, Step by Step

Quick Answer: Publish one SPF record listing your senders, switch on DKIM in your email platform and add its key to DNS, then publish a DMARC record starting at p=none. Verify with a checker, read the first reports, and only then tighten DMARC. Done in this order, a full SPF, DKIM, and DMARC setup takes an afternoon plus a few weeks of monitoring.

The steps below assume a common Malaysian SME stack — Google Workspace or Microsoft 365 for mail, with DNS at your domain registrar. The exact values differ by platform, but the order never changes.

How to set up SPF, DKIM, and DMARC

  1. Publish one SPF record. Add a single DNS TXT record listing every service that sends for you, for example v=spf1 include:_spf.google.com ~all for Google Workspace. One record only, ending in ~all.
  2. Turn on DKIM. Generate the DKIM key in your email platform’s admin console, then publish the key it gives you as a TXT record at the selector it specifies. Use a 2048-bit key where offered.
  3. Publish a DMARC record. Add a TXT record at _dmarc.yourdomain.com such as v=DMARC1; p=none; rua=mailto:[email protected]. Starting at p=none monitors without blocking anything.
  4. Verify everything passes. Send a test email to a Gmail account, open the headers, and confirm SPF, DKIM, and DMARC all read “pass”. A free checker tool confirms the same in seconds.
  5. Read the reports, then tighten. DMARC aggregate reports arrive within days. Once you confirm your real mail is passing, move the policy from p=none toward quarantine and then reject.

That is the whole job. The only step people rush is the last one — tightening the policy before checking the reports, which can block legitimate mail. Patience here is the difference between protection and a self-inflicted outage.

Key takeaway: SPF first, DKIM second, DMARC third — always in that order, always starting DMARC on p=none. Verify a real send passes before you tighten anything.

Want the records set up and verified for you?

We handle the DNS, the DKIM keys, and the DMARC rollout end to end. Explore our digital marketing services →


6. Why a p=none DMARC Policy Isn’t Real Protection

Quick Answer: A DMARC policy of p=none only watches — it tells receivers to do nothing when mail fails. It is the right place to start, but stopping there means spoofers can still send as you. Real protection begins at quarantine and reject. Most local domains that have DMARC never move past monitor mode.

DMARC has three enforcement levels. None reports but takes no action. Quarantine sends failing mail to spam. Reject blocks it outright. Only the last two actually stop someone impersonating your domain. Yet in our audits, most DMARC-enabled domains sit on p=none long after they should have moved on.

DMARC Enforcement Level — Domains That Have DMARC
Share of DMARC-enabled Malaysian SME domains by enforcement policy level, from ZenWeb audits.
DMARC policyShare of DMARC domains
p=none (monitor only)

61%

p=quarantine

27%

p=reject (full protection)

12%

Source: ZenWeb DMARC audits, Malaysian SME sample, 2024–2026. Figures illustrative of typical patterns.

Only about one in eight reaches reject, where impersonation is truly blocked. Monitor mode is a starting line, not a finish. Leaving it there is also what makes rebuilding a ruined sender domain reputation slower than it needs to be, because spoofed mail keeps damaging your name.

Key takeaway: Start at p=none to watch, but plan to move to quarantine then reject. A DMARC record that never enforces is a smoke alarm with the battery out.

7. Rolling Out DMARC Safely, Stage by Stage

Quick Answer: Move DMARC up in stages, not in one jump. Monitor on p=none for two weeks, then quarantine a small percentage of mail, ramp that percentage up, then switch to full quarantine, and finally reject. The pct tag lets you enforce on a slice of mail first, so any misconfigured sender surfaces before it can block everyone.

The goal is to reach reject without ever bouncing your own legitimate mail. Ramping the percentage gives you a safety valve at each step. The timeline below is a sensible default for a small sender; larger or more complex setups take longer.

Recommended DMARC Rollout Timeline
Recommended staged DMARC enforcement timeline for a small sender, illustrative scenario.
StageWeeksPolicyMail enforced
Monitor1–2p=none0%
Soft-fail start3–4p=quarantine; pct=55%
Ramp up5–6p=quarantine; pct=2525%
Full quarantine7–8p=quarantine100%
Enforce9+p=reject100%

Source: ZenWeb recommended rollout, illustrative scenario for a small Malaysian sender.

Key takeaway: Use the pct tag to enforce on a slice of mail first, then ramp. Reaching reject over eight to nine weeks is safe; jumping there on day one is how you block your own invoices.

8. How to Check Your Setup Is Working

Quick Answer: Don’t assume — verify. Send a test email to Gmail and read the headers for SPF, DKIM, and DMARC “pass”. Then run your domain through a free authentication checker, and connect Google Postmaster Tools to watch your spam rate and reputation. These three checks confirm the setup holds, not just that the records exist.

Checking takes minutes and saves weeks of guessing. Bulk senders also have a hard bar to clear here. Per Google’s Email sender guidelines, anyone sending more than 5,000 messages a day to Gmail must have SPF, DKIM, and DMARC in place and keep the spam-complaint rate in Postmaster Tools below 0.30%.

  • Header check. Send yourself a message at a Gmail address, open “Show original”, and confirm all three lines read “pass”.
  • Authentication checker. Run your domain through a free SPF, DKIM, and DMARC lookup tool to catch lookup limits, duplicate records, or a missing selector.
  • Postmaster Tools. Connect your domain and watch spam rate, domain reputation, and authentication pass rates as you send.

Reputation is not only about records. Engagement still counts, so a signal like a high unsubscribe rate can drag placement down even when authentication is perfect. Monitor both.

Key takeaway: A header check plus Postmaster Tools tells you the setup is truly passing, not just published. If you send in bulk, staying under a 0.30% spam rate is non-negotiable.

9. Fix It Yourself, or Bring in Help

Quick Answer: Publishing SPF, turning on DKIM, and starting DMARC on p=none is a fair DIY job for most owners. Bring in help when you send from several tools, when SPF keeps hitting the lookup limit, or when reaching reject safely matters because real revenue rides on the mail. Those are the points where one wrong record hides for months.

Here is the rough line for when to call someone in.

  • Do it yourself when you run one mail platform, need the three records added, and just want a clean pass confirmed with a header check.
  • Get help when multiple senders share your domain, SPF keeps breaking the ten-lookup limit, or you cannot risk blocking invoices and quotes while you learn.

The stakes rise once your pipeline depends on email arriving. That is where our digital marketing team steps in: we set the records, run the DMARC rollout, and monitor it so it stays fixed. It is the same diagnostic habit you want when rankings drop suddenly — find the real cause before you act on the symptom.

Key takeaway: Handle the basic records yourself. Bring in help for multi-sender setups and the move to reject, where the cost of a silent mistake is months of lost mail.

10. Conclusion

Emails failing to land feels like a content problem, but it is usually a plumbing problem. SPF, DKIM, and DMARC are the plumbing. Publish all three, start DMARC on p=none, verify a real send passes, then tighten toward reject over a few weeks. That sequence fixes the biggest single cause of poor deliverability for Malaysian SMEs.

The one thing that never works is leaving it half-done and hoping. If you would rather have your SPF, DKIM, and DMARC setup done and monitored properly the first time, the team at ZenWeb does exactly that.


11. Frequently Asked Questions

1. What is SPF, DKIM, and DMARC setup, in simple terms?

It means publishing three DNS records that prove your email is really from you. SPF lists the servers allowed to send for your domain, DKIM adds a signature that shows the message wasn’t altered, and DMARC tells receivers what to do when a check fails and emails you reports. Together they are the standard for a trusted sender.

2. Do I really need all three, or is SPF enough?

You need all three. SPF alone is the most common setup, but it doesn’t prove message integrity or protect against spoofing. Gmail and Yahoo now expect SPF, DKIM, and DMARC together from bulk senders, and mailbox providers trust a fully authenticated domain far more than one running SPF on its own.

3. What DMARC policy should I start with?

Start with p=none. It monitors and reports without blocking any mail, so you can confirm your legitimate senders pass before enforcing. Once the reports look clean, move to p=quarantine, then p=reject. Jumping straight to reject risks blocking your own email, so ramp up in stages instead.

4. How long does it take for SPF, DKIM, and DMARC to work?

The records themselves take effect once DNS updates, usually within a few hours. Authentication then passes on your next send. Reaching full DMARC enforcement safely takes longer — plan on eight to nine weeks of monitoring and ramping the policy so you never block legitimate mail on the way to reject.

5. Will setting up DMARC block my own emails?

Not if you roll it out properly. On p=none nothing is blocked. The risk only appears if you jump to quarantine or reject before confirming your real senders pass. Read the aggregate reports first, fix any sender that fails, and ramp the pct tag up gradually — done that way, only spoofed mail gets blocked.

Emails still landing in spam?

Book a free 30-minute session. We’ll check your SPF, DKIM, and DMARC records, your sender reputation, and your list health, then give you a clear plan to get your emails back in the inbox where they earn leads.

Get my free deliverability review →

Table of Contents

Table of Contents

See Also

Blasting Emails but No Sales? How to Fix Your Email Strategy

Blasting Emails but No Sales? How to Fix Your Email Strategy

Email Bounce Rate Too High? How to Clean Your Sending List

Email Bounce Rate Too High? How to Clean Your Sending List

Emails Land in Promotions Tab? How to Reach the Inbox

Emails Land in Promotions Tab? How to Reach the Inbox

Get A Free Proposal

Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Meowketing Specialist

Online

Today

Meow! 👋

We are Official Google Partner,
Ask us anything about Marketing!