How to configure SPF, DKIM, and DMARC for your custom domain
If your mail sometimes lands in spam, the cause is almost always authentication rather than content. SPF, DKIM, and DMARC are three DNS records that let receiving servers confirm a message really came from your domain. Set them up once and your deliverability improves for good.
SPF — who is allowed to send
SPF (Sender Policy Framework) is a TXT record listing the servers permitted to send mail for your domain. When Airfree Mail sends on your behalf, the receiver checks this record and confirms our servers are authorised.
example.com. TXT "v=spf1 include:_spf.airfreemail.com ~all"DKIM — a tamper-proof signature
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message. The receiver fetches your public key from DNS and verifies the signature, proving the message was not altered in transit. Airfree Mail generates the key pair for you; you publish the public half as a TXT record at the selector we provide.
airfree._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSq..."DMARC — the policy that ties it together
DMARC tells receivers what to do when SPF or DKIM fails, and where to send reports. Start with p=none to monitor without affecting delivery, read the aggregate reports for a couple of weeks, then tighten to quarantine and finally reject.
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=s; aspf=s"Verifying it works
After publishing the records, send a message to a Gmail address and use "Show original" to confirm SPF, DKIM, and DMARC all show PASS. In Airfree Mail, the domain settings page runs the same checks and flags any record that is missing or malformed.
Ready for a private inbox?
Airfree Mail is zero-knowledge email on sovereign infrastructure. Import from Gmail in minutes.
Create your free account →