# From Spoofed to Secured: Setup Guides by Platform ## From Spoofed to Secured Step-by-step SPF, DKIM, and DMARC instructions for the providers you already use — plus free tools to generate and check your records. ### The Email Authentication Stack Four layers that take a domain from spoofable to brand-verified. Implement them in order for the fewest surprises. 1. **SPF** — Authorize which servers can send mail for your domain. 2. **DKIM** — Cryptographically sign outbound messages so receivers can verify integrity. 3. **DMARC** — Set policy and reporting so spoofed mail can be monitored — then enforced. 4. **BIMI** — Show your brand logo in supporting inboxes (requires DMARC enforcement). ### Guides by Platform Choose your email provider. Use Generator and Checker to build and validate records while you follow DNS steps in your host’s console. ### Why Generic Guides Fail Copy-paste tutorials skip the details that actually break authentication on your stack. - **DNS formatting quirks**: Hosts disagree on quotes, TTL defaults, and multi-string TXT records — one wrong character and SPF or DMARC never publishes. - **Multi-sender complexity**: Marketing tools, CRMs, and support desks each need includes and keys. Generic guides rarely map your full sender inventory. - **DKIM selector & key pitfalls**: Wrong selectors, truncated public keys, or dual-provider signing leave mail unsigned while dashboards claim “DKIM is on.” ### Free Tools to Build & Verify Records Generate clean records, then validate them before you flip DMARC to quarantine or reject. - [DMARC Generator](/tools/dmarc-generator) - [DMARC Checker](/tools/dmarc-checker) - [SPF Generator](/tools/spf-generator) - [DKIM Checker](/tools/dkim-checker) ## Start monitoring your DMARC reports free No credit card required. See who sends as your domain and move from monitoring to enforcement with confidence.