What these records actually tell you

SPF publishes which hosts are authorized to send mail for a domain used in the SMTP envelope. DMARC tells receivers how the domain owner wants messages handled when neither aligned SPF nor aligned DKIM passes. A policy in DNS is a configuration statement, not a record of how an individual message was authenticated.

Inspect SPF at the envelope sender domain and DMARC at _dmarc.domain. A message can pass SPF for a different domain while failing DMARC alignment with the visible From address. Preserve the original email and authentication headers when investigating a specific message.

Interpreting the policy

An SPF record begins v=spf1. The ~all mechanism expresses softfail; -all expresses fail. A softfail does not mean that a DMARC policy has failed. DMARC records begin v=DMARC1 and p=none, p=quarantine or p=reject specifies the requested handling policy for messages that fail DMARC.

The rua tag names aggregate reporting destinations. Those addresses are not necessarily the domain operator. DMARC is concerned with the domain shown in From; it does not prevent every form of display-name deception or lookalike-domain abuse.

An investigator’s checklist

Separate record presence, syntax and policy from per-message authentication. DNS records alone cannot determine whether a sender is legitimate.

  • Record the exact query name, resolver, UTC collection time and returned TXT values.
  • Preserve the original .eml message; inspect trusted Authentication-Results headers.
  • Compare the visible From domain to the authenticated SPF/DKIM domain.
  • Treat missing or permissive policies as contextual indicators, not a fraud verdict.

Sources and further reading

RFC 7208 — Sender Policy FrameworkRFC 7489 — DMARC
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.