Authentication
SPF, DKIM, DMARC, transport security, and domain trust.
3 topics in this category.
About this category
This section collects production-verified specifications, implementation standards, and operational guidelines for authentication. Each specification provides clear compliance levels (Required, Recommended, Optional, or Avoid) alongside concrete testing methods and platform considerations.
Topics
Sender Policy Framework (SPF)
RequiredPublish a single, bounded SPF policy that authorizes legitimate envelope senders without exceeding the 10-DNS-lookup limit or using overly permissive qualifiers.
DomainKeys Identified Mail (DKIM) Signatures
RequiredCryptographically sign outgoing email messages with DKIM using aligned domains, minimum 2048-bit keys, canonicalization, and regular selector rotation.
Domain-based Message Authentication, Reporting, and Conformance (DMARC)
RequiredEnforce domain-aligned email authentication with a DMARC policy that instructs receivers how to handle unauthenticated mail and generates aggregate feedback reports.