← All articles
deliverability

SPF, DKIM and DMARC Explained for Ecommerce Teams

26 April 2026

SPF, DKIM and DMARC Explained for Ecommerce Teams

If your marketing emails land in the spam folder, your revenue suffers immediately. Following the 2024 updates to bulk-sender requirements from Gmail and Yahoo, technical authentication is no longer an optional "best practice"—it is a strict requirement for staying in the inbox.

For many founders and marketing managers, the technical side of email marketing for ecommerce feels like a distraction from creative and commercial goals. However, ignoring SPF, DKIM, and DMARC is the fastest way to see your open rates plummet and your hard-earned list go to waste.

This guide explains these protocols in plain English and provides a checklist to ensure your brand remains compliant.

Why Authentication Matters for Ecommerce

Email is the primary driver of retention and repeat purchases. While industry reports vary, data from sources like the DMA often suggest that email marketing remains one of the highest-ROI channels available, frequently cited as contributing roughly a fifth of total orders for well-optimised ecommerce stores.

When you send an email, the recipient's provider (Gmail, Outlook, iCloud) asks two questions: "Is this sender who they say they are?" and "Has this message been tampered with?"

Authentication provides the digital ID cards that answer these questions. Without them, your emails look like phishing attempts or unsolicited spam. Since February 2024, if you send more than 5,000 emails a day to Gmail or Yahoo addresses, these protocols are mandatory. Even if you send fewer, failing to set them up increases the risk of your automated flows (like abandoned carts) being blocked.

SPF: The Authorised Guest List

Sender Policy Framework (SPF) is a DNS record that lists the specific IP addresses and domains authorised to send email on behalf of your domain.

Think of your domain as a private club. SPF is the guest list at the door. If a mail server receives an email claiming to be from your brand, it checks your SPF record. If the server that sent the mail isn't on the list, the email is flagged.

For ecommerce brands using platforms like Klaviyo, Shopify, or Brevo, your SPF record must include these providers. Most domains only allow one SPF record; if you have multiple, they must be merged into a single string. Having two separate SPF records is a common technical error that causes authentication to fail entirely.

DKIM: The Digital Wax Seal

DomainKeys Identified Mail (DKIM) adds a cryptographic signature to your emails. This acts like a digital wax seal on an envelope.

When your ESP (Email Service Provider) sends an email, it attaches a hidden signature to the header. The receiving server uses a public key—stored in your DNS records—to verify that signature. If the email was intercepted or changed in transit, the seal is broken, and the authentication fails.

DKIM is vital for ecommerce because it proves the integrity of your content. It ensures that the "Buy Now" link or the price in your promotional email is exactly what you sent, protecting both your brand reputation and your customers.

DMARC: The Instruction Manual

Domain-based Message Authentication, Reporting, and Conformance (DMARC) is the most important of the three for 2024 compliance. DMARC tells the receiving server what to do if an email fails SPF or DKIM checks.

Without DMARC, the receiving server decides what to do with a suspicious email. With DMARC, you give the instructions. There are three policy levels:

  1. p=none (Monitor): No action is taken against failed emails, but you receive reports. This is the minimum requirement for the new bulk-sender rules.
  2. p=quarantine: Emails that fail authentication are sent to the spam folder.
  3. p=reject: Emails that fail authentication are blocked entirely.

For most ecommerce teams starting out, a p=none policy is the standard entry point. It satisfies the Gmail/Yahoo requirements while allowing you to monitor your traffic and ensure your legitimate emails (from your ESP, helpdesk, or transactional systems) are authenticating correctly before moving to a stricter policy.

The 2024 Bulk-Sender Requirements

Google and Yahoo have made it clear: if you do not have these three records in place, your deliverability will suffer. Beyond authentication, they have also formalised requirements for one-click unsubscriptions and a strict spam complaint threshold.

According to Google’s own documentation, senders must keep their spam complaint rate (as reported in Google Postmaster Tools) below 0.3%. Crossing this threshold consistently will lead to your emails being deferred or blocked, regardless of your authentication status.

Effective email marketing for ecommerce requires a balance between technical health and content quality. If your technical setup is perfect but your content is irrelevant, your spam rates will rise, and your authentication won't save you.

Setup Checklist for Ecommerce Managers

Use this checklist to audit your current setup. Most of these tasks require access to your DNS provider (e.g., GoDaddy, Namecheap, Cloudflare, or Google Domains).

TaskDescriptionStatus
Branded Sending DomainEnsure you are sending from mail.yourbrand.com rather than a shared ESP domain.[ ]
SPF RecordVerify your SPF record includes all current tools (Klaviyo, Gorgias, Zendesk, Shopify).[ ]
DKIM AlignmentCheck that your DKIM signature matches the domain in your "From" address.[ ]
DMARC RecordEnsure a DMARC record exists with at least a p=none policy.[ ]
One-Click UnsubscribeConfirm your ESP automatically includes the List-Unsubscribe header.[ ]
Postmaster ToolsSet up Google Postmaster Tools to monitor your domain reputation and spam rates.[ ]

Common Pitfalls to Avoid

In our work as an agency, we frequently see brands making the same three mistakes:

  1. Using a Gmail/Yahoo address in the "From" field: You cannot authenticate a @gmail.com address for your brand. You must use a custom domain (e.g., hello@yourbrand.com).
  2. Multiple SPF records: As mentioned, you must consolidate your SPF into one line. A record like v=spf1 include:spf.klaviyo.com include:_spf.google.com ~all is correct; having two separate lines starting with v=spf1 is not.
  3. Ignoring Transactional Mail: Ensure your transactional emails (order confirmations, shipping updates) are also authenticated. These often come from a different system than your marketing blasts, such as Shopify's internal mailer or an app like ShipStation.

How to Test Your Setup

You don't need to be a developer to check if your email marketing for ecommerce is technically sound. Tools like Mail-Tester or AboutMy.email allow you to send a test message to a specific address and receive a report on your SPF, DKIM, and DMARC status.

Additionally, platforms like Klaviyo now provide in-app alerts if your DNS records are not configured to meet the latest requirements. If you see a warning badge in your account settings, prioritise fixing it immediately.

The Long-Term Benefit

While these requirements feel like a hurdle, they are actually a benefit to legitimate ecommerce brands. By raising the bar for entry, major inbox providers are making it harder for bad actors and low-quality spammers to reach the inbox.

When your domain is fully authenticated, you build a "reputation" with providers. This reputation acts like a credit score. The better your score, the more likely your emails are to land in the Primary tab rather than the Promotions or Spam folders. In the competitive landscape of email marketing for ecommerce, these marginal gains in deliverability translate directly to increased revenue.

Related reading

Work with us

If you are concerned about your deliverability or need help navigating the technical requirements of modern email marketing, we can help. Inboxwave specialises in technical audits and revenue-focused email strategies for ecommerce brands. Get in touch today to book a discovery call and ensure your emails are reaching your customers.