Skip to main content

Email authentication: a marketer's guide

Email authentication: a marketer's guide

August 4, 2026

Michael Taylor

Michael Taylor

Chief Customer Officer

Email authentication is how inbox providers decide whether to trust you. Get it right and your email lands, your logo can show up beside it, and your sender reputation compounds. Get it wrong and you are guessing why your open rates slipped. Three protocols do the work, a fourth puts your logo in the inbox, and none of it requires an engineer once you know what you are looking at.

Key takeaways

  • Email authentication runs on three protocols: SPF, DKIM, and DMARC. Each answers a different question about whether a message is really from you.
  • Google and Yahoo have required bulk senders to publish a DMARC record since February 2024, at p=none or stronger. If you send at volume to consumer inboxes, this is a condition of delivery. See Gmail and Yahoo sending requirements for the full list.
  • DMARC enforcement (p=quarantine or p=reject) is a separate, higher bar. It is what actually protects your domain from spoofing, and it is what BIMI requires.
  • BIMI is the payoff, not the point. It puts your verified logo in Gmail, Yahoo Mail, and Apple Mail. Since September 2024 you no longer need a registered trademark to qualify in Gmail, and Yahoo and Fastmail will show a logo with no certificate at all.

What is email authentication?

Email authentication is a set of DNS-based standards that let inbox providers verify a message really came from the domain it claims. It replaces trust-by-appearance with trust-by-proof. Without it, anyone can put your domain in a From line, and inbox providers have no way to tell your email from a phishing attempt wearing your name.

That matters to you for two reasons that pull in the same direction. Authenticated email is more likely to reach the inbox, because providers treat verified senders better. And authenticated email is harder to impersonate, which protects the customers who trust your name enough to open your messages.

What are the email authentication protocols?

The email authentication protocols are SPF, DKIM, and DMARC, and they work as a stack rather than a menu. SPF lists which servers may send for your domain. DKIM adds a cryptographic signature proving the message was not altered in transit. DMARC ties the two together, tells providers what to do when a check fails, and sends you reports on what is happening.

Here is what each one actually does:

  • SPF, or Sender Policy Framework. A DNS record listing the servers authorized to send email for your domain. If a message arrives from somewhere else, SPF fails.
  • DKIM, or DomainKeys Identified Mail. A signature added to each message, checked against a public key in your DNS. It proves the message is intact and came from you.
  • DMARC, or Domain-based Message Authentication, Reporting and Conformance. Your policy instruction to inbox providers: none, quarantine, or reject. It also delivers reports showing who is sending as you.
  • SPF and DKIM without DMARC is the most common gap. The checks run, but nothing tells the provider what to do when they fail, and you never see the reports. Left unchecked, that is also how domains end up on blocklists.

How do I authenticate my email?

To authenticate your email you publish three DNS records, move your DMARC policy from monitoring to enforcement, and confirm every service that sends on your behalf is covered. The work is mostly DNS and coordination, not engineering. Expect a few weeks if you send from more than one platform.

  1. Inventory every domain and service that sends as you. Marketing platform, transactional email, invoicing, support desk, and anything sales tools send. Missing one is the usual reason authentication breaks later.
  2. Publish an SPF record listing every authorized sender you just inventoried.
  3. Enable DKIM signing on each sending platform and publish the matching public keys in DNS.
  4. Publish a DMARC record at p=none. This is monitoring mode. It changes nothing about delivery, it starts the reports flowing, and it is the minimum Google and Yahoo ask of bulk senders.
  5. Read the reports for a few weeks. Find legitimate senders that are failing and fix them before you enforce anything.
  6. Move DMARC to p=quarantine, then p=reject. This goes beyond the Google and Yahoo minimum. It is the step that actually stops spoofing, and the step that unlocks BIMI.

If you want the wider version of this list, including the sending practices that sit alongside authentication, work through the deliverability checklist.

How does email authentication affect email deliverability?

Email authentication affects email deliverability indirectly but substantially. Inbox providers use authentication results as a trust input, so authenticated email clears filters more easily and builds sender reputation faster. Unauthenticated email from a domain that could be spoofed gets treated with suspicion, and that suspicion shows up as inbox placement you cannot explain.

The clearest evidence is the requirement itself. In February 2024 Google and Yahoo made a DMARC record mandatory for bulk senders, which turned authentication from a best practice into a condition of delivery at the two largest consumer inboxes. Google also holds bulk senders to a spam complaint rate below 0.10%, with 0.30% treated as a hard ceiling. Our guide to the Gmail and Yahoo sending requirements covers what changed, and Microsoft’s sender requirements followed a similar path.

What authentication will not do is rescue bad sending habits. It proves you are you. It does not prove anyone wanted the message. Permission, list hygiene, and spam complaint rates still decide whether your reputation holds, which is why the single vs double opt-in question sits right alongside this one. Giving people an easy exit through Gmail’s subscription dashboard helps for the same reason.

Once your emails are landing, the next question is what to measure. That is what our guide to email marketing analytics is for.

Where does BIMI fit in email authentication?

BIMI sits at the end of email authentication as its visible reward. Brand Indicators for Message Identification lets you publish your logo in DNS so participating inboxes display it beside your messages. It is the only part of authentication your customers actually see, and it is the only part that requires everything else to already be working.

Gmail, Yahoo Mail, Apple Mail, and Fastmail all display BIMI logos. Microsoft does not. Outlook.com, Hotmail, Exchange Online, and Microsoft 365 show sender initials instead, and Microsoft has not announced a date, though it has tightened its rules elsewhere: see Microsoft’s sender requirements. Segment your list by mailbox provider before you budget for BIMI, because that ratio decides the payoff.

You have three ways to assert a logo, and they are not equally supported. Most guides skip straight to certificates and miss the first one.

  1. Self-asserted logo. No certificate at all. You host the SVG over HTTPS, publish the BIMI record, and keep DMARC at enforcement. Yahoo, Fastmail, and La Poste honour self-asserted logos. Gmail does not. This is the cheapest way to start.
  2. Common Mark Certificate. Covers logos that are not registered trademarks, either through a documented history of prior use or a registered mark you have since modified. Gmail began supporting CMCs on 24 September 2024, which is what opened BIMI up to brands without a trademark.
  3. Verified Mark Certificate. For registered trademarks or government-recognised marks. The most rigorous, and the only type that earns the verified checkmark in Gmail. Google is explicit that a CMC displays your logo without it.

Two things are non-negotiable whichever route you take. DMARC has to be at quarantine or reject, and your logo has to be a square SVG saved to the Tiny Portable/Secure profile. Certificate requirements beyond that are set by the certificate authority, so ask yours what evidence of prior use it wants before you budget the time.

Test before you count on it. In a January 2025 analysis of the top 1 million domains, 53.6% of domains publishing a BIMI record had at least one configuration error, up from 41.8% in May 2024. The most common problem by far is an SVG file that does not meet the spec, which affected 27.5% of them. A DMARC policy still sitting at none accounted for another 13.3%.

One specific trap worth checking if you already have a certificate. Apple stopped trusting Entrust-issued Verified Mark Certificates created after 15 November 2024, which knocked out BIMI display for 132 domains in the top million, Business Insider and Best Buy among them. Recipients on icloud.com, mac.com, and me.com stop seeing the logo. If your VMC came from Entrust after that date, you need a different certificate authority.

Strengthen your email authentication with Acoustic

Email authentication is table stakes. What you do with the trust it earns is where the results come from. Acoustic reads what your customers actually do, then sends from the same system that saw the behavior, so the message arrives while the moment is still open.

Book an Acoustic demo to see how behavioral triggers, SMS, and email run from one platform. Our professional services team also works through DMARC, VMC, and CMC specifics with customers every week if you want help mapping your sending domains first, and our one-pager on how to maximize deliverability covers the sending side.

Email authentication FAQs

What happens to email authentication when you switch email platforms?

Your SPF record and DKIM keys are tied to the platforms you send from, so both need updating before you move traffic or authentication will fail on the new sender. Acoustic’s onboarding covers the DNS changes as part of migration, so authenticated sending carries over instead of breaking on your first send.

How often should email authentication records be reviewed?

Review them any time you add or remove a sending tool, and read your DMARC reports at least monthly to catch new senders you did not authorize. Because Acoustic sends email, SMS, WhatsApp, and push from one platform, there are fewer separate senders to keep authenticated in the first place.

Do subdomains need their own email authentication?

Subdomains inherit your DMARC policy by default unless you set a separate subdomain policy, but they still need their own DKIM keys and SPF coverage for whatever sends from them. Keeping marketing, transactional, and behavioral sends on one platform means one set of records to maintain rather than one per tool.

Can adding a new marketing tool break email authentication?

Yes. Any new service that sends as your domain will fail authentication until you add it to SPF and publish its DKIM key, and under an enforced DMARC policy those messages get quarantined or rejected. Consolidating channels onto one platform removes most of that risk, since new campaigns run through sending infrastructure that is already authenticated.

Michael Taylor

Michael Taylor

Chief Customer Officer

Transform how you connect with your customers

Acoustic Connect helps you create campaigns that adapt to real-time behaviors, turning everyday interactions into long-term loyalty.