信任 · Email Authentication
SPF、DKIM 和 DMARC 设置指南
邮件 authentication records 是 sender reputation 的基础。缺少它们,即使发送基础设施配置良好,消息也可能被过滤、拒收或进入 spam。
代表性产品 UI — 示例数据,并非实时客户指标。
为什么重要
为什么 authentication records 对 deliverability 很重要
Mailbox provider 会判断发送基础设施是否由 domain owner 授权。SPF、DKIM 和 DMARC 建立这种 authorization。
当这些 records 缺失或配置错误时,provider 会将 email 视为 unauthenticated,即使来自合法发送服务。Deliverability monitoring 无法弥补缺失的 authentication。
SPF — Sender Policy Framework
SPF 授权特定 mail servers 代表你的 domain 发送邮件。它以 DNS TXT record 发布。Receiver 收到消息时查询发送 domain 的 SPF record;如果发送 server 不在列表中,消息 fails SPF。
按发送 source 的 record 示例
仅 Sendarix SMTP relay
v=spf1 include:sendarix.com ~allGmail / Google Workspace
v=spf1 include:_spf.google.com ~allMicrosoft 365 / Outlook
v=spf1 include:spf.protection.outlook.com ~allSendarix + Google 组合
v=spf1 include:sendarix.com include:_spf.google.com ~all常见 SPF 错误
- Record 中超过 10 个 DNS lookups 会在部分 receiver 产生
PERMERROR。 - 使用
~all(softfail) 而不是-all(fail) 会形成 receiver 视为宽松的弱 policy。 - 切换 provider 后忘记发送服务,会让旧 provider 继续发送并 fails SPF。
- Include 拥有自己 SPF records 的 domains 会增加 nested lookups。
DKIM — DomainKeys Identified Mail
DKIM 给 outgoing email headers 添加 cryptographic signature。Receiver 使用 DNS 中的 public key 验证消息在 transit 中未被修改,并来自其声明的 domain。它使用 selector-based record(如 selector2._domainkey.example.com)。
selector2._domainkey.yoursendingdomain.com IN TXT ("v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA...")
Sendarix dashboard 为每个 sending domain 提供完整 DKIM record。
SPF 覆盖
- 哪些 servers 被授权代表你的 domain 发送
- Envelope MAIL FROM address 伪造
- 用于发送的 unauthorized subdomains
DKIM 覆盖
- Transit 中 header/body 未修改的 message integrity
- Headers 中 From domain 的真实性
- 与可见 From address 的 alignment
DMARC alignment 需要两者。只用 SPF 而不用 DKIM 会让 domain 易受部分 spoofing attacks。
DMARC — Authentication, Reporting & Conformance
DMARC 基于 SPF 和 DKIM,告诉 receivers 在 authentication 失败时如何处理,并提供 reporting 以监控谁代表你的 domain 发送。
Policy 级别
p=none — monitoring
失败时不采取动作;你会收到 aggregate reports。用于 enforcement 前 audit setup。
p=quarantine — partial
失败消息进入 spam/junk。这是 full enforcement 前推荐的中间步骤。
p=reject — full
Receivers 拒收失败消息。仅在所有 legitimate sources 的 SPF 和 DKIM 正确后使用。
标准 DMARC record
_dmarc.yoursendingdomain.com IN TXT ("v=DMARC1; p=none; rua=mailto:dmarc-reports@yoursendingdomain.com; pct=100")
Alignment 要求
消息通过 DMARC 需要 SPF 和 DKIM 都 authenticate,且至少一个与可见 From domain align。
- SPF alignment: envelope MAIL FROM domain 必须匹配 From header domain,或是其 subdomain。
- DKIM alignment: signature 中的
d=domain 必须匹配 From header domain,或是其 subdomain。 - 注意: 使用不同于 From domain 的 MAIL FROM domain(bulk services 常见)需要 strict alignment,否则会失败。
推荐设置顺序
在 audit 发送 source 前急于 full DMARC enforcement 会导致 legitimate email 被拒。请按此顺序执行。
1. Audit 所有发送 source
列出使用你的 domain 发送的每个 service、server 和 workflow:marketing tools、CRM、helpdesks 和 transactional services。
2. 发布 SPF
通过 include: mechanism 添加所有 sending services。减少 nested includes,保持在 10-lookup limit 以下。
3. 发布 DKIM
每个 service 提供自己的 selector。按 service 添加 record。Sendarix DKIM records 位于 dashboard 的 domain settings。
4. 设置 p=none 并 review
监控 2-4 周。检查 rua reports 中 legitimate mail failing,并修复缺失的 SPF/DKIM sources。
5. Quarantine 然后 reject
所有 legitimate sources authenticate 后,升级到 quarantine,再经过一个 audit period 后升级到 reject。
按 provider 的 authentication guides
每个大型 mailbox provider 都有特定要求。请与 Sendarix sending-domain records 一起配置。
Gmail SMTP settings
Custom domains 需要 SPF + DKIM。Bulk-sender rules 包括 SPF、DKIM 和 valid From address。
Outlook SMTP configuration
Microsoft 使用 SPF、DKIM,并越来越多使用 DMARC 进行 filtering。Office 365 senders 有单独要求。
Yahoo SMTP settings
需要 SPF + DKIM,并正向某些 volume thresholds 以上 mandatory DMARC 发展。
Office 365 SMTP setup
Connectors 有 strict policies;增强 deliverability 需要 DKIM signing。
Amazon SES configuration
默认提供 DKIM signing,但 deliverability 仍需 manual SPF configuration。
SendGrid SMTP settings
Domain Authentication 替代 manual DKIM setup。SPF 仍必须手动配置。
准备好配置 sending domain 了吗?
Sendarix 为每个 sending domain 提供 DKIM records,并在 dashboard 中引导你完成完整 authentication setup。
