BlogSPF, DKIM, and DMARC: what to check when mail starts missing the inbox
SPF, DKIM, and DMARC: what to check when mail starts missing the inbox

When delivery drops after a tool or DNS change, start with authentication alignment—not a vague warmup checklist.
Start with the cause, not the symptom
Spam-folder spikes and failed warmups often share the same root: SPF, DKIM, or DMARC no longer match how mail is actually sent.
What to inspect first
- SPF — does the record authorize the servers and tools that send today?
- DKIM — are messages signed with a key that still exists and aligns with the From domain?
- DMARC — is policy set, and do SPF/DKIM results align with the organizational domain?
Then check subdomain and tool overlap. New ESPs, forwarding, and “helpful” DNS edits are common break points.
Validate after changes
Fix in a safe order, then confirm with the same signals mailbox providers use. The free Inbox Placement Test is a practical first pass; request a deliverability audit when you need a fix list and ownership notes.
