SaaSEmailDeliverabilitySPFDKIMDMARC

SaaS Email Deliverability: SPF, DKIM, DMARC Setup

Maximize email deliverability for your SaaS with proper SPF, DKIM, and DMARC configuration, covering setup steps, monitoring, and common pitfalls.

Maya Patel
Maya Patel
June 8, 202610 min read

TL;DR: Email deliverability determines whether your transactional emails reach users or land in spam. SPF, DKIM, and DMARC are DNS records that authenticate your sending domain. This guide covers the setup process for each protocol, testing with your email provider (Resend, SendGrid, AWS SES), and monitoring deliverability.


Introduction

Your SaaS sends emails: welcome emails, password resets, invoices, notifications. If these land in spam, your customer experience suffers and support tickets increase. Email authentication -- SPF, DKIM, DMARC -- tells receiving mail servers that your emails are legitimate.


DNS Record Setup

To authenticate your email, you need to add three types of DNS records to your domain. These records tell receiving mail servers that your emails are legitimate and should be delivered to the inbox rather than the spam folder. Below are the exact DNS entry formats for SPF (authorizing senders), DKIM (signing emails with cryptographic keys), and DMARC (setting policies for unauthenticated mail):

dns
; SPF record - authorize your email provider
example.com.  TXT  "v=spf1 include:spf.resend.com ~all"

; DKIM record - sign your emails
resend._domainkey.example.com.  TXT  "v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC..."

; DMARC record - policy for unauthenticated mail
_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@example.com"

Each record serves a distinct purpose in the authentication chain: SPF declares which servers are allowed to send email on your behalf, DKIM provides a cryptographic signature that verifies the email hasn't been tampered with, and DMARC tells receiving servers what to do when SPF or DKIM checks fail. All three are required for optimal deliverability.


DMARC Policy Progression

PolicyMeaningWhen to Use
p=noneMonitor only, no actionInitial setup (1-2 weeks)
p=quarantineSend failures to spamAfter monitoring phase (2-4 weeks)
p=rejectReject failures entirelyAfter confirming no false positives

Conclusion

Proper email authentication is essential for SaaS deliverability. Set up SPF, DKIM, and DMARC records before sending customer emails. Start with DMARC p=none to monitor, then progress to p=quarantine and p=reject. To complement your email authentication setup, our SaaS Customer Support Guide covers how to manage customer email communications effectively, and the Email Marketing Automation guide explains how to maintain sender reputation at scale. For a broader view of protecting your infrastructure, see SaaS Security Best Practices.