## TL;DR

If your verification emails land in spam or vanish, publish SPF and DKIM records for your sending domain. SPF authorizes your mail server in DNS, DKIM cryptographically signs each message, and together they tell receivers the mail is legitimate. Check both with a DNS lookup, then watch bounces for a week.

```text
email deliverability for verification mails (SPF/DKIM basics)
```

## Use this when

- Setting up a domain that sends verification or notification mail
- Verification emails land in spam
- A receiver rejects your mail with an authentication error

## Not for this skill when

- You send through a provider that handles this for you (check their docs first)
- The problem is content or reputation, not authentication
- You do not control the sending domain's DNS

## Steps

1. Confirm the sending domain and its DNS control. You need to add TXT records, so you need DNS access. Expected: you can publish records for the domain.

2. Publish an SPF record. A TXT record at the domain root listing your authorized senders. Expected: receivers can verify your server is allowed.

```
TXT @ "v=spf1 include:mail.example.net ~all"
```

3. Add DKIM signing. Generate a key pair, publish the public key as a TXT record under a selector, and configure your mailer to sign outbound mail. Expected: sent mail carries a valid DKIM signature.

```
TXT dkim1._domainkey "v=DKIM1; k=rsa; p=[public key]"
```

4. Align the From domain. The visible From address should match the domain you authenticated; mismatches fail DMARC on strict receivers. Expected: From, SPF domain, and DKIM domain agree.

5. Verify with lookups and a test send. Query the TXT records and send to a seed address, then check the authentication results headers. Expected: SPF pass and DKIM pass in the headers.

```
check: dig TXT example.com
check: dig TXT dkim1._domainkey.example.com
```

6. Publish a DMARC record in monitor mode. Start with `p=none` to get reports without rejecting mail. Expected: aggregate reports show your authentication posture.

## Variant phrasings

### SPF record for sending verification emails

A TXT record authorizing your mail servers; without it, receivers treat your mail as suspicious.

### DKIM setup for a new sending domain

Generate a key pair, publish the public key under a selector, sign outbound mail.

### verification emails going to spam

Check SPF and DKIM first, then From alignment, then content and reputation.

## Why it happens

Receiving mail servers assume unauthenticated mail is forged, because most of it is. SPF and DKIM are the two proofs a small sender can offer; without them, your verification mail looks exactly like the phishing it resembles, and filters act accordingly.

## Edge cases / pitfalls

- Multiple SPF records break SPF; keep exactly one TXT record starting with v=spf1.
- The 10-DNS-lookup SPF limit is real; flatten includes if you exceed it.
- DKIM selectors must match what your mailer signs with; a typo means silent failure.
- Forwarding breaks SPF; DKIM usually survives, which is why you want both.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_KRcSL_FfI2qlV9Ze8845yQ
