Skip to content
DMARC123Policy Management Simplified

SPF, DKIM, and DMARC

Email authentication works best when the signals are evaluated together.

SPF identifies authorized sending infrastructure. DKIM adds a verifiable domain signature. DMARC evaluates alignment, publishes handling policy, and tells receivers where to send reports. DMARC123 connects those controls to the evidence received from mailbox providers.

SPF

Authorize sending systems without confusing authentication with alignment.

SPF evaluates whether the connecting server is authorized to send for the envelope domain. A message can pass SPF but still fail DMARC alignment when the authenticated envelope domain differs from the visible From domain.

DMARC123 preserves this distinction so expected third-party or multi-domain sending is not automatically presented as a problem when aligned DKIM already allows DMARC to pass.

DKIM

Use cryptographic signatures to establish aligned domain identity.

DKIM signatures can survive forwarding more reliably than SPF because the signature travels with the message. DMARC123 examines the reported selector, signing domain, authentication result, and alignment with the managed domain.

Multiple reported signatures remain evidence-level data rather than being collapsed into one misleading value.

DMARC

Publish policy and use receiver evidence to improve enforcement safely.

DMARC policies progress from monitoring to quarantine or rejection. Aggregate reports show source volume, SPF and DKIM outcomes, and policy disposition. Failure reports can provide message-specific forensic evidence where receivers support them.

DMARC123 turns that evidence into operational categories and keeps policy, DNS setup, validation, and reporting connected.

Practical guidance

Do not chase alignment metrics in isolation.

A lower SPF-alignment rate is not automatically a deliverability problem when DKIM is aligned and DMARC passes. Investigate actual failures, unexpected infrastructure, and receiver disposition before changing valid sending configurations.

See product features

Built and operated by PM Technologies

Bring policy, validation, and reporting together.

Existing users can sign in. Organizations evaluating DMARC123 can contact PM Technologies to discuss account access and deployment.