Inventory every legitimate sender
Before tightening policy, identify Google Workspace, website forms, CRM systems, marketing platforms, support tools and any other service authorized to send as the domain.
Email Authentication
SPF, DKIM and DMARC are separate controls that work together. SPF identifies authorized senders, DKIM adds a cryptographic signature and DMARC evaluates domain alignment and defines how failures should be handled and reported.

A broken SPF record can cause legitimate sources to fail authentication.
Missing DKIM removes an important cryptographic identity signal.
An aggressive DMARC policy deployed too early can reject legitimate business mail.
Enter your domain to check its public email records. The results show what we found and what needs a closer look. This check cannot confirm inbox placement. You do not need to enter an email address.
Before tightening policy, identify Google Workspace, website forms, CRM systems, marketing platforms, support tools and any other service authorized to send as the domain.
Authentication is useful when the visible From domain aligns with the identities validated by SPF or DKIM. That relationship matters more than the presence of three DNS records.
Monitoring can reveal legitimate services that are not aligned. Enforcement should follow evidence rather than a copied p=reject record.
Help investigating and fixing email authentication, spam placement, routing and delivery problems.
For a specific email authentication or delivery problem.
For recurring delivery problems involving several possible causes.
For complex setups, high sending volumes or several domains.