# From Spoofed to Secured: Setup Guides by Platform

## From Spoofed to Secured

Step-by-step SPF, DKIM, and DMARC instructions for the providers you already use — plus free tools to generate and check your records.

### The Email Authentication Stack

Four layers that take a domain from spoofable to brand-verified. Implement them in order for the fewest surprises.

1. **SPF** — Authorize which servers can send mail for your domain.
2. **DKIM** — Cryptographically sign outbound messages so receivers can verify integrity.
3. **DMARC** — Set policy and reporting so spoofed mail can be monitored — then enforced.
4. **BIMI** — Show your brand logo in supporting inboxes (requires DMARC enforcement).

### Guides by Platform

Choose your email provider. Use Generator and Checker to build and validate records while you follow DNS steps in your host’s console.

### Why Generic Guides Fail

Copy-paste tutorials skip the details that actually break authentication on your stack.

- **DNS formatting quirks**: Hosts disagree on quotes, TTL defaults, and multi-string TXT records — one wrong character and SPF or DMARC never publishes.
- **Multi-sender complexity**: Marketing tools, CRMs, and support desks each need includes and keys. Generic guides rarely map your full sender inventory.
- **DKIM selector & key pitfalls**: Wrong selectors, truncated public keys, or dual-provider signing leave mail unsigned while dashboards claim “DKIM is on.”

### Free Tools to Build & Verify Records

Generate clean records, then validate them before you flip DMARC to quarantine or reject.

- [DMARC Generator](/tools/dmarc-generator)
- [DMARC Checker](/tools/dmarc-checker)
- [SPF Generator](/tools/spf-generator)
- [DKIM Checker](/tools/dkim-checker)

## Start monitoring your DMARC reports free

No credit card required. See who sends as your domain and move from monitoring to enforcement with confidence.

View HTML page