SCANTIDE ONLINE
Scantide Online Guide

SPF, DKIM and DMARC Explained

SPF, DKIM and DMARC are related but different email-authentication controls. Together they help receiving systems evaluate whether a message claiming to use your domain is legitimate.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: SPF, DKIM and DMARC are related but different email-authentication controls. Together they help receiving systems evaluate whether a message claiming to use your domain is legitimate.

SPF authorizes sending infrastructure

SPF publishes which systems are allowed to send mail for a domain. Forwarding and complex mail flows can affect how SPF behaves.

DKIM signs message content and identity

DKIM uses cryptographic signatures so a receiver can verify that signed parts of a message were not altered and that the signing domain takes responsibility for the message.

DMARC connects identity and policy

DMARC evaluates alignment between the visible From domain and SPF/DKIM results, and lets a domain publish policy and reporting preferences.

Public DNS makes these controls observable

Scantide Online can review public SPF and DMARC posture as part of the wider domain assessment. DKIM review depends on knowing or discovering the relevant selector.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: Domain Security Scanner for DNS, HTTPS and Web Exposure

Use Scantide Online to check DNS and mail security, HTTPS/TLS, security headers, cookies and public infrastructure context from one domain scan.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Scantide Online – Domain Security, Privacy and Infrastructure Scanner

A single domain can expose signals across DNS, mail, HTTPS, headers and infrastructure. Scantide Online brings those observations into one readable assessment.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also make sure your servers are set correctly in regards to SPF (yep, link in Swedish) and not to accept emails from your own domain from anywhere else than the servers you actually can control and validate.

On the subject of DNS servers. There's absolutely no point in having your DNS servers reachable through the firewall thus enabling attackers to flood it with DNS queries and UDP floods.

Practical review checklist

Frequently asked questions

Does SPF alone stop spoofing?

No. SPF does not by itself protect the visible From address in every scenario; DMARC alignment is important.

Can a domain have DMARC without rejecting mail?

Yes. Monitoring policies are commonly used before stricter enforcement.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides