Overview
Most major email and support systems verify whether a message actually originates from the domain it claims to represent. A domain without correctly configured SPF and DKIM may have its emails bounced, marked as spam, or dropped entirely, including emails sent to a support desk.
What Is Email Authentication?
| Standard | What It Checks | If Missing or Failing |
|---|---|---|
| SPF (Sender Policy Framework) | Which mail servers are authorized to send on behalf of the domain | Message may be rejected or marked as spam |
| DKIM (DomainKeys Identified Mail) | Whether the message content was altered after sending | Message integrity cannot be verified; may be rejected or flagged |
| DMARC (Domain-based Message Authentication, Reporting and Conformance) | How receivers should handle messages that fail SPF or DKIM | Receiver decides independently, often by rejecting the message |
All three are DNS records. Major mail providers (Gmail, Outlook, Yahoo) have applied versions of these checks by default for years, and more platforms are moving to enforce a minimum standard rather than leaving it optional.
Why This Matters
- This is the standard. Major mail providers have applied SPF and DKIM checks by default. A domain missing either one is likely already experiencing delivery problems with many recipients, not only one support desk.
- Not vendor-specific. A failing domain can see the same issue across multiple providers and tools, not just one.
- Defaults are getting stricter. More support and ticketing systems are moving toward suspending or rejecting email from unauthenticated domains by default.
- No warning. Failed messages are typically suspended or dropped silently, with no bounce-back notice.
- Industry direction, not just one policy. PCI DSS v4.0.1 now recommends anti-phishing controls, including DMARC, for organizations handling cardholder data. Email authentication is becoming an expectation across the payments industry generally.
- Fallback: If a domain fails these checks, email to a support desk may be suspended or may never arrive. If that happens, use the support portal's web form and ticket view instead of email until the domain issue is resolved.
The most reliable outcome is achieved by maintaining both a valid SPF record and a valid DKIM record for any domain used to send email, including to support desks.
Prerequisites
- Access to the domain's DNS settings, either directly or through whoever manages the domain. This might be an internal IT team, a web developer, a website hosting company, or the domain registrar (the company the domain was purchased through).
- A list of every system that sends email on behalf of the domain, since each may need to be added to the SPF record.
How It Works
- Identify all domains used to send email, including any used for support correspondence.
- Check current SPF/DKIM/DMARC status with a DNS lookup tool (e.g., MXToolbox,
dig,nslookup). - Work with an IT team, web developer, hosting company, or domain registrar to correct or add records. See the provider table below for common setup guides.
- Allow up to 48 hours for DNS propagation, then re-check.
Provider-Specific Setup Guides
These are external links and may change if the provider updates their site.
Troubleshooting
| Symptom | Likely Cause | Resolution |
|---|---|---|
| Support emails aren't getting replies or creating tickets | SPF/DKIM missing or failing | Check DNS records and correct with your IT team or domain registrar |
| Only some tools' emails are delivered | Not all sending systems are in the SPF record | Add the missing service to SPF |
| Fix applied, but check still fails | DNS hasn't propagated yet | Wait up to 48 hours, re-check |
Note: Authentication failures usually happen without a bounce-back notice. Missing replies are a good early signal to check DNS records.
Key Definitions
- Domain: The part of a website or email address that identifies an organization online; for example, "google.com." It usually appears after the "@" in an email address or after "www." in a website address, and is typically the same for a company's website and its email.
- DNS (Domain Name System): A system that works like an address book for the internet, connecting a domain name to the technical settings that make a website, email, and other services work correctly.
- DNS record: A small entry stored in a domain's DNS settings that provides specific information about that domain, such as which mail servers are allowed to send email on its behalf.
- SPF (Sender Policy Framework): A DNS record listing which mail servers are allowed to send email for a domain.
- DKIM (DomainKeys Identified Mail): A digital signature added to outgoing email that proves its content hasn't been changed in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance): A DNS record that tells receiving mail servers what to do if a message fails SPF or DKIM.
- Domain administrator / IT team: The person or company responsible for managing a domain's technical settings. This could be an internal IT staff member, a web developer, a website hosting company, or the domain registrar.
- Domain registrar: The company a domain was purchased through (for example, GoDaddy, Namecheap, or Google Domains). If it's unclear who manages a domain's settings, the registrar is a good place to start.