[{"data":1,"prerenderedAt":87},["ShallowReactive",2],{"tool-guide:email-authentication":3},{"overview":4,"whatIs":5,"useCases":6,"commonMistakes":12,"relatedStandards":18,"comparison":28,"steps":65,"example":69,"limitations":73,"faq":77},"Email Authentication Toolkit constructs SPF, DKIM, and DMARC DNS names, optionally retrieves public TXT records through the disclosed Cloudflare DNS-over-HTTPS resolver, and analyzes or generates bounded records locally.","Email authentication is the set of DNS-based mechanisms that let receiving mail servers verify whether an email was actually sent by the domain it claims to be from. The three core protocols — SPF, DKIM, and DMARC — work together to prevent email spoofing and phishing. SPF (Sender Policy Framework) publishes a list of authorized sending servers in a DNS TXT record. DKIM (DomainKeys Identified Mail) uses a cryptographic signature in the email header, verified against a public key in DNS, to prove the message was sent by the domain and was not altered. DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together with a policy that tells receiving servers what to do when authentication fails, and where to send reports. This toolkit helps you look up existing SPF, DKIM, and DMARC records for any domain, analyze their syntax for correctness, and generate new records with a guided builder. DNS lookups use the Cloudflare DNS-over-HTTPS resolver; record analysis and generation run entirely in your browser.",[7,8,9,10,11],"Setting up email authentication for a new domain — generate SPF, DKIM selector, and DMARC records before publishing them in DNS.","Auditing an existing domain — look up and analyze current SPF, DKIM, and DMARC records to identify syntax errors, weak policies, or missing records.","Troubleshooting delivery failures — check whether SPF includes your sending service, whether the DKIM selector record exists, and whether DMARC is set to reject or quarantine.","Migrating email providers — verify that SPF includes the new provider and that DKIM selectors are published before switching MX records.","Training and education — look up real-world SPF, DKIM, and DMARC records to understand how email authentication works in practice.",[13,14,15,16,17],"SPF \"all\" mechanism — using ~all (softfail) instead of -all (hardfail) provides weaker protection. However, switching to -all before confirming all legitimate senders are listed can cause delivery failures.","Too many SPF lookups — SPF has a 10-DNS-lookup limit. Each \"include\" and \"redirect\" counts. Exceeding the limit causes a PermError, which fails SPF for all messages.","Wrong DKIM selector — DKIM records are published at selector._domainkey.example.com. The selector must match what your email provider signs with. Check your provider documentation for the correct selector.","DMARC without SPF and DKIM — DMARC requires at least one of SPF or DKIM to pass and align. Publishing a DMARC record without functioning SPF or DKIM authentication provides no protection.","Missing DMARC rua address — without a reporting address (rua=), you receive no aggregate reports and cannot monitor authentication results for your domain.",[19,22,25],{"title":20,"url":21},"RFC 7208 — SPF","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc7208",{"title":23,"url":24},"RFC 6376 — DKIM Signatures","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc6376",{"title":26,"url":27},"RFC 7489 — DMARC","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc7489",{"heading":29,"columns":30,"rows":35},"SPF vs DKIM vs DMARC",[31,32,33,34],"Feature","SPF","DKIM","DMARC",[36,42,48,54,60],{"label":37,"values":38},"What it checks",[39,40,41],"Sending server IP","Message signature","SPF\u002FDKIM alignment with From header",{"label":43,"values":44},"DNS record type",[45,46,47],"TXT on domain","TXT on selector._domainkey.domain","TXT on _dmarc.domain",{"label":49,"values":50},"Survives forwarding",[51,52,53],"No (IP changes)","Yes (signature intact)","Depends on SPF\u002FDKIM",{"label":55,"values":56},"Policy enforcement",[57,58,59],"Pass\u002Ffail\u002Fsoftfail","Pass\u002Ffail","None\u002Fquarantine\u002Freject",{"label":61,"values":62},"Reporting",[63,63,64],"No","Yes (aggregate + forensic)",[66,67,68],"Choose SPF, DKIM, or DMARC. Enter a domain and, for DKIM, its selector; review the exact TXT query and provider disclosure before looking it up.","Paste a record or select a matching DNS answer to review syntax and cautious policy diagnostics.","Configure the local generator, copy the resulting TXT value, and validate it with your mail provider before publishing it in DNS.",{"label":70,"input":71,"output":72},"Enforcing SPF syntax","v=spf1 include:_spf.example.com -all","Syntax checks passed · hard fail policy detected",[74,75,76],"DNS lookup is an explicit network action: the queried name and TXT type appear in the HTTPS GET URL and Cloudflare receives normal connection metadata.","Syntax checks do not recursively evaluate SPF, verify a DKIM signature, validate DNSSEC independently, or authenticate a message.","Generation does not publish DNS, create DKIM keypairs, confirm report-address authorization, or replace testing with your email provider.",[78,81,84],{"question":79,"answer":80},"What is SPF?","SPF (Sender Policy Framework) is a DNS TXT record that lists which servers are authorized to send email for a domain. Receiving servers check SPF to help detect forged sender addresses.",{"question":82,"answer":83},"What is DKIM?","DKIM (DomainKeys Identified Mail) uses a cryptographic signature in the email header and a public key in DNS to let receivers verify that a message was sent by the domain it claims and was not altered in transit.",{"question":85,"answer":86},"Does this tool generate DKIM keys?","No. The generator creates the DNS TXT record syntax for SPF, DKIM selector records, and DMARC policies. DKIM keypair generation should be done through your email provider or server.",1788868141370]