How to set up SPF, DKIM and DMARC so your business email stops landing in spam
Does your quote end up in the customer's spam folder, or never arrive at all? Since 2024, Gmail, Outlook.com and Yahoo require every business domain to prove its email is genuine. You deliver that proof with three DNS records: SPF, DKIM and DMARC. This guide walks you through setting them up correctly, whether you send through Microsoft 365, Google Workspace or a Dutch hosting provider.
Published 28 September 2026 · 14 min read · by Joep de Kok, IT specialist at Geekie Creative & IT · Lees dit artikel in het Nederlands
Why your email lands in spam (and what the big receivers require)
Email was designed in 1982 without any check on the sender (RFC 821). Anyone can send a message with your address in the From field, and the receiving server has no way of its own to tell whether that message really came from you. Fraudsters take full advantage of this: the Dutch fraud helpdesk (Fraudehelpdesk) recorded more than five times as many phishing reports in the first half of 2026 as a year earlier, and email was the channel in 59% of reports, up from 30% (Fraudehelpdesk, half-year figures 2026).
The large mailbox providers have therefore tightened their rules. Senders who ignore them first see their mail land in spam, then get rejected. These are the current requirements:
| Receiver | All senders | More than 5,000 messages a day |
|---|---|---|
| Gmail | SPF or DKIM (one of the two), valid PTR record (reverse DNS), encrypted connection (TLS), spam rate below 0.3% | both SPF and DKIM, DMARC (at least p=none), From domain aligned with SPF or DKIM, one-click unsubscribe |
| Outlook.com, Hotmail, Live | No hard requirement, but reputation and spam filtering apply | both SPF and DKIM, DMARC at least p=none (reject recommended), otherwise error 550 5.7.515 |
| Yahoo | SPF or DKIM (one of the two), spam rate below 0.3% | both SPF and DKIM, DMARC at least p=none, one-click unsubscribe |
Google has enforced these rules since February 2024 and in November 2025 started actually rejecting mail that does not meet them (Google, email sender guidelines FAQ). Microsoft has done the same for Outlook.com since 5 May 2025 (Microsoft, error 550 5.7.515). The 5,000-message threshold applies per domain per day, and once you have crossed it, Google treats you as a bulk sender permanently.
Most small businesses never reach 5,000. This still matters to you: to a spam filter, a domain without DKIM and DMARC is a domain anyone can send from, and that counts against you in every assessment. The three records are also the cheapest defence against CEO fraud and fake invoices in your name. For businesses covered by the Dutch Cybersecurity Act (NIS2) (article in Dutch), or supplying such businesses, it is one of the first questions on the customer's checklist.
SPF, DKIM and DMARC in plain English
All three records live in your domain's DNS, the address book of the internet that you manage at the company where your domain name is registered. Each does something different, and they only really work once all three are in place.
1 · SPF
The guest list
A list of servers allowed to send for your domain. The receiver checks whether the server delivering the message is on that list. If it is not, that is suspicious.
2 · DKIM
The wax seal
Your mail server puts a digital signature on every message. The receiver verifies it with a key from your DNS. If the signature checks out, the message was not altered in transit and really came from your domain.
3 · DMARC
The house rules plus the report
Tells the receiver what to do when both SPF and DKIM fail: nothing, put it in spam, or refuse it. And it sends you a daily report about all mail sent with your domain, including mail sent by others.
One term will come back later: alignment. DMARC does not just check whether SPF or DKIM passes, but also whether the domain that passed is the same as the domain in the From address the recipient sees. A newsletter service sending from its own servers with its own signature passes technically, but not on your domain. That is why you need to enable DKIM for your own domain at every service that sends on your behalf.
Where does the Netherlands stand?
Better than a few years ago, but the final step is missing almost everywhere. Statistics Netherlands (CBS) measures every year, via internet.nl, how businesses with two or more employees are doing. In 2026, nine in ten business domains had an SPF record and more than eight in ten had DKIM. DMARC is present on two thirds of domains, but two in three of those sit in non-binding monitoring mode.
Only 22.3% of businesses pass the complete authentication category of the test (a different figure from the 22.8% with strict DMARC above), up from 17.4% in 2025 and 8.0% in 2023 (CBS, 2026).
For comparison: within the Dutch government, where the three standards fall under ‘comply or explain’, 86% of domains already had a strict DMARC policy at the start of 2026 (Forum Standaardisatie (the Dutch government's standardisation forum), early 2026 measurement). Globally the picture is even more skewed: of 73 million domains analysed at the end of 2025, 83.9% had no DMARC record at all and 2.5% were at reject (Red Sift, December 2025).
The takeaway: publishing SPF and DKIM is now normal. Set DMARC to reject as well and you join the best-protected quarter of Dutch businesses, and your customers notice it as an inbox without fake invoices in your name.
Before you start: three things to line up
- Access to your domain's DNS. Usually that is the control panel of the company where you registered the domain name (TransIP, STRATO, Hostnet, Mijndomein, Vimexx, KPN) or Cloudflare if you put that in front of it. Not sure? Your web developer usually knows.
- A list of everything that sends mail for your domain. Not just Outlook or Gmail, but also the accounting package that sends invoices, the newsletter tool, the CRM, the webshop, the contact form on the website, the office scanner. Every forgotten sender will end up in spam later.
- A baseline. Enter your domain at internet.nl/test-mail, the free test run by the Dutch government and the internet community. Save the result so you can see the difference later. For your website we offer a similar free website check (in Dutch).
Do the steps in this order. Google recommends waiting 48 hours between publishing SPF and DKIM and publishing DMARC, so the changes have propagated everywhere.
Step 1: publish an SPF record for your domain
After this step, your DNS holds one TXT record naming every server allowed to send for your domain. An SPF record is a single line of text: it always starts with v=spf1, then names the permitted senders (usually via include:) and ends with what should happen to everyone else.
| Name / host | @ (or yourcompany.com) |
|---|---|
| Type | TXT |
| Value | v=spf1 include:spf.protection.outlook.com -all |
That is the record for a business sending exclusively through Microsoft 365. The value for your situation depends on your mail platform:
| Mail platform | SPF value | Note |
|---|---|---|
| Microsoft 365 | v=spf1 include:spf.protection.outlook.com -all | Microsoft recommends -all (Microsoft Learn). |
| Google Workspace | v=spf1 include:_spf.google.com ~all | Google recommends ~all (Google Workspace Admin Help). |
| TransIP (web hosting, Email Only) | v=spf1 include:_spf.transip.email ~all | Per the TransIP knowledge base. |
| Mijndomein | v=spf1 a mx include:spf.mijndomeinhosting.nl ~all | Per the Mijndomein help desk. |
| STRATO | Pick the predefined 'STRATO SPF rule' in DNS management | It publishes v=spf1 redirect=_spf.strato.com. If you also send through other services, create your own record instead (STRATO FAQ). |
| Hostnet | v=spf1 a mx include:_spf.hostnet.nl -all | Per the Hostnet help desk. |
| Vimexx | Copy the record from DirectAdmin → DNS Management | Vimexx uses IP addresses instead of an include (Vimexx help). |
| KPN (own domain on KPN mail, article in Dutch) | No official guide; ask KPN for the value | In the KPN Community a KPN employee names include:spf.ews.kpnxchange.com. KPN signs DKIM with kpnmail.nl, not with your domain; see step 2. |
If you send through several services, put all the includes in the same record. A business with Microsoft 365 and a newsletter service ends up with, for example, v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net -all. The newsletter service's include is in its documentation.
Three rules where it usually goes wrong
- One SPF record per domain. Two records means receivers declare both invalid (RFC 7208). Is there already a record? Add your include to it.
- At most ten DNS lookups. Every
include,a,mxandredirectcounts, including the includes nested inside an include. Above ten, the whole record is invalid. Microsoft 365's own include already uses several, for example. - Never
+all. It literally means anyone may send for you. Choose~all(softfail) or-all(hardfail). The Dutch National Cyber Security Centre (NCSC) prefers~all, because a hardfail can block legitimate mail before DKIM and DMARC have even been evaluated (NCSC). With DMARC in place, the difference matters little in practice.
Step 2: enable DKIM signing at your mail platform
After this step, your mail platform signs every outgoing message with a key that belongs to your own domain. You do not build DKIM yourself: the platform generates the key, you publish a pointer in your DNS and then switch signing on. This is the step most often skipped, and exactly the step DMARC will rely on.
Microsoft 365
- Open the Microsoft Defender portal and go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings, tab DKIM.
- Click your domain, then Create DKIM keys. Microsoft shows two CNAME records:
selector1._domainkeyandselector2._domainkey. A selector is simply the name under which a key is stored in your DNS. - Publish both as CNAME in your DNS, with exactly the value from the portal. Note: for domains added to Microsoft 365 since May 2025, the value ends in
dkim.mail.microsoft; for older domains it ends inonmicrosoft.com. Older guides online only show the old format, so always copy from the portal. - Wait until the records are visible, then switch on Sign messages for this domain with DKIM signatures.
The default key is 1024 bits; with PowerShell (Rotate-DkimSigningConfig -Identity yourcompany.com -KeySize 2048) you upgrade it to 2048 bits, the length the NCSC recommends. Full details are on Microsoft Learn.
Google Workspace
- Open the Google Admin console and go to Apps → Google Workspace → Gmail → Authenticate email.
- Select your domain, click Generate new record and choose a 2048-bit key if your DNS provider supports it (almost all Dutch providers do).
- Publish the TXT record shown on host
google._domainkeyin your DNS. - After at most 48 hours, click Start authentication. The status changes to ‘Authenticating email with DKIM’ (Google Workspace Admin Help).
Dutch hosting providers
- STRATO already signs all mail sent via smtp.strato.com with DKIM; the two CNAME records (
strato-dkim-0002._domainkeyandstrato-dkim-0003._domainkey) are in DNS management by default (STRATO FAQ). - Hostnet enables DKIM automatically when your name servers (the servers that publish your DNS) are at Hostnet. If they are elsewhere, copy the records from Mijn Hostnet under Diensten → your domain → E-mail → DKIM beheren (Hostnet help desk).
- Vimexx shows the DKIM record (
x._domainkey) in DirectAdmin under DNS Management; copy it to your DNS if that lives elsewhere. - TransIP and Mijndomein describe DKIM in their own knowledge bases; search there for ‘DKIM’ to find the record for your plan.
- KPN signs mail from a custom domain with the domain kpnmail.nl, as a KPN employee confirms in the KPN Community. Technically that is DKIM, but it is not your domain, so DMARC sees it as unaligned. If you want to reach reject, moving to Microsoft 365 or Google Workspace is the practical route. We help with that regularly.
Do not forget the other senders on your list. Almost every newsletter service, accounting package and CRM has a page called ‘verify your domain’ or ‘set up DKIM’ where you get one or two CNAME records. Do it for every service, or their mail will fail DMARC later.
Step 3: publish a DMARC record in monitoring mode (p=none)
After this step, Google, Microsoft and other receivers send you a daily report, without anything happening to your mail yet. The record is a TXT record on the host _dmarc. First create a mailbox or alias for the reports, for example dmarc@yourcompany.com, then publish this record:
| Name / host | _dmarc |
|---|---|
| Type | TXT |
| Value | v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com |
That is all you need to begin. These are the parts of the record:
| Tag | Meaning | What to enter |
|---|---|---|
v=DMARC1 | Version | Required, always exactly like this. |
p= | Policy | none (report only), quarantine (to spam) or reject (refuse). |
rua=mailto: | Report address | Where the daily aggregate reports are sent. |
sp= | Subdomain policy | Leave it out and p= applies to subdomains as well. |
adkim= / aspf= | Alignment strictness | r (relaxed, default) or s (strict). Keep r unless you know why not. |
pct= | Percentage | Existed in the old standard; removed in RFC 9989 (2026). Many receivers still understand it, but do not rely on it. |
DMARC has been an official internet standard since June 2026, defined in RFC 9989, which replaces the old RFC 7489 (SIDN). Little changes for you: the record above works under both versions. Only the pct= tag, which older guides still use to apply the policy partially, has been dropped from the standard.
Want the reports to go to a different domain than the one the record is on, for example to a reporting service? Then the receiver expects a small authorisation record on that other domain: a TXT record named yourcompany.com._report._dmarc with the value v=DMARC1;. The services in step 4 show the exact record for their domain.
Step 4: read the reports and find forgotten senders
After this step, you know exactly which servers send for your domain and which of them pass SPF and DKIM. The reports arrive as XML attachments, which are unreadable to the naked eye. Let a free service translate them into an overview per sender:
| Service | What you get | Note |
|---|---|---|
| Postmark DMARC Digests | A readable weekly email with the ten largest senders and their results. | Email only, no dashboard. Ideal for a small business. |
| Cloudflare DMARC Management | Dashboard per sending source, including the authorisation record. | Only if your DNS is at Cloudflare; works on the free plan. |
| Valimail Monitor | Recognises services (Microsoft, Mailchimp, Exact) by name and shows pass/fail per service. | Free, no credit card; an account is required. |
One frequently recommended service you cannot use from the Netherlands: since February 2024 the website of dmarcian shows Dutch visitors only a notice that the service is unavailable here under a court ruling. Pick one of the three above.
Read the reports for at least four weeks. That period also catches the monthly senders: the invoice run, the newsletter, the annual reminder from the scanner. For every source you recognise but that fails, go back to step 1 (add the include) or step 2 (enable DKIM). For sources you do not recognise, do nothing: those are the forgeries you will keep out with reject later.
Step 5: move the policy to quarantine, then reject
After this step, forgeries in your name disappear into the recipient's spam folder or are refused outright. Do it in two stages, because a premature reject blocks your own mail just as hard as the fraudsters'.
- All known senders passing in the reports? Change
p=nonetop=quarantine. Forgeries now land in spam. Keep reading the reports. - Still clean two to four weeks later? Set
p=reject. This is the end state the NCSC recommends and that Microsoft and Google describe as the goal.
| Name / host | _dmarc |
|---|---|
| Type | TXT |
| Value | v=DMARC1; p=reject; rua=mailto:dmarc@yourcompany.com |
Do you have subdomains that send mail, such as news.yourcompany.com? They inherit the main domain's policy unless you specify otherwise with sp=. Do you own domain names that never send mail, for example the .nl variant of your name or an old brand? Protect those too, because fraudsters pick exactly those domains. Two records suffice: an SPF record v=spf1 -all and a DMARC record v=DMARC1; p=reject;. Both the NCSC and Forum Standaardisatie explicitly recommend this for domains that do not send mail.
Checking that everything works
When everything is in place, you will see three things. On internet.nl the ‘DMARC, DKIM and SPF’ section turns green. In the DMARC reports, nearly 100% of mail from your own sources passes. And a test message to a Gmail address shows PASS three times under Show original: for SPF, DKIM and DMARC.
- internet.nl/test-mail: the complete Dutch test, including DNSSEC and STARTTLS. Compare with your baseline.
- MXToolbox: shows your SPF record including the number of DNS lookups, and validates the DMARC syntax.
- Google Check MX: checks MX and SPF and, if you enter the selector, your DKIM key.
Common mistakes
Two SPF records
The web developer added one for the contact form, you added one for Microsoft 365. Receivers now declare both invalid. Merge all includes into a single record.
Going straight to p=reject
Without a monitoring phase you do not know which services send for you. The first to notice is your bookkeeper, when the invoices from the accounting package stop arriving. Always start at p=none.
DKIM record as TXT instead of CNAME
Microsoft 365 and STRATO use CNAME records; Google Workspace and Vimexx use TXT. Take the type from your platform's guide, not from another platform's example.
Domain name doubled in the host name
Many DNS panels append your domain to the host automatically. Enter only selector1._domainkey, not selector1._domainkey.yourcompany.com. After saving, check what is actually there.
Forgotten senders
The website contact form, the network scanner, the point-of-sale system and the ticketing tool all send mail in your name. Every source missing from SPF or DKIM stops arriving once you reach p=reject. The reports from step 4 are your safety net.
Unused domains left unprotected
Your .nl, your old trading name and that one campaign domain: without SPF and DMARC they are a free sender address for fraudsters. Publish v=spf1 -all and p=reject on them.
Frequently asked questions
Why does my email still land in spam when SPF is set up correctly?+
SPF on its own is not enough. Gmail, Outlook.com and Yahoo also look at DKIM and DMARC, at your spam rate and at your domain's reputation. SPF also checks the technical sender address (the envelope), not the address the recipient sees. If a newsletter tool sends on your behalf, SPF often passes on that tool's domain rather than yours. Enable DKIM at every service that sends for your domain and publish a DMARC record; the reports will then show you exactly where it fails.
SPF and DKIM pass, but DMARC fails. How is that possible?+
Besides a passing check, DMARC requires 'alignment': the domain that passed SPF or DKIM must match the domain in the From address. If your provider signs with its own domain (KPN, for example, signs with kpnmail.nl) or a mailing service uses its own envelope address, the check passes, but on the wrong domain. The fix is to have DKIM sign with your own domain, which Microsoft 365, Google Workspace and most mailing services support.
Is DMARC mandatory for my business?+
No law requires a small business to use DMARC. For the Dutch government it is a 'comply or explain' standard. In practice it has been a requirement of the large mailbox providers since 2024 and 2025: Google and Yahoo require SPF or DKIM from everyone, and SPF, DKIM and DMARC from anyone sending more than 5,000 messages a day to their users; Microsoft applies the same bulk rule to Outlook.com. Stay below that and you will not be fined, but your chance of landing in the spam folder keeps growing. And for businesses covered by NIS2, or supplying such businesses, email security is part of the basic hygiene customers ask about.
I send through Microsoft 365 and a newsletter tool. Which SPF record should I use?+
One record with both includes, for example v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net -all (the second include is in your newsletter tool's documentation). Never publish two separate SPF records; receivers will reject both. Also count the DNS lookups: SPF allows at most ten, and every include counts, including the includes nested inside it. If you are near the limit, move the newsletter to a subdomain such as news.yourcompany.com with its own record.
How long does it take before SPF, DKIM and DMARC work?+
DNS changes are usually visible within an hour, but Google allows up to 48 hours for DKIM and recommends publishing DMARC 48 hours after SPF and DKIM. The real work is the monitoring phase: expect four to eight weeks on p=none to see every sender in the reports, then a few weeks on quarantine, and only then reject.
Sources
All requirements and figures in this article come from the mailbox providers' official documentation, the standards themselves and Dutch government measurements, retrieved on 28 September 2026.
- Google: Email sender guidelines
- Microsoft: Outlook.com Postmaster, sender policies
- Yahoo: Sender Hub, best practices
- Statistics Netherlands (CBS): Internet standards on business websites, 2026
- Forum Standaardisatie: Information security standards measurement, early 2026
- NCSC-NL: Protect your domains against phishing
- Fraudehelpdesk: half-year figures 2026
- Red Sift: Guide to global DMARC adoption (December 2025)
- RFC 7208 (SPF), RFC 6376 (DKIM) and RFC 9989 (DMARC)
- Microsoft Learn: Set up SPF, DKIM and DMARC for Microsoft 365
- Google Workspace: Set up DMARC
Further reading
Rather have it done for you? We set it up in an afternoon.
Geekie Creative & IT sets up SPF, DKIM and DMARC for businesses in the Rotterdam area, including the monitoring phase and the move to reject. Even if your domain sits with KPN, STRATO or a web developer. You get a fixed price up front and a green tick on internet.nl afterwards.