Email security guides
Plain-language explanations of the records that decide whether your domain can be spoofed and whether your mail reaches the inbox, each with example records and the fixes AstraVerify recommends.
- What is SPF? Sender Policy Framework explained
SPF (Sender Policy Framework) is a DNS TXT record listing the servers allowed to send email for your domain. Learn the syntax, what -all and ~all mean, the 10-lookup limit, and how to fix common SPF mistakes.
- What is DKIM? DomainKeys Identified Mail explained
DKIM (DomainKeys Identified Mail) signs outgoing email with a private key and publishes the public key in DNS under a selector. Learn how DKIM works, what a selector is, why 2048-bit keys matter, and how to find and fix your DKIM setup.
- What is DMARC? Policies, alignment and reports explained
DMARC tells receiving mail servers what to do when a message fails SPF and DKIM alignment, and sends you reports about who is sending as your domain. Learn the p=none, quarantine and reject policies, alignment, and a safe rollout order.
- What are MX records? How email routing works
MX (mail exchanger) records tell the world which servers accept email for your domain. Learn how priority works, why redundancy matters, what a null MX is, and the common MX mistakes that break email delivery.
- How the AstraVerify email security score works
AstraVerify scores a domain out of 100: MX 25, SPF 25, DKIM 20 and DMARC 30 points, with bonuses for strict settings. Learn what earns and loses points, why a score is capped while a fix is open, and how to reach 100.