[{"data":1,"prerenderedAt":342},["ShallowReactive",2],{"navigation":3,"\u002Fdocs\u002Fguides\u002Fspf-dkim-dmarc\u002F":72,"\u002Fdocs\u002Fguides\u002Fspf-dkim-dmarc\u002F-surround":337},[4,8,22,26,43],{"title":5,"path":6,"stem":7},"Getting Started","\u002Fdocs\u002Fgetting-started","1.docs\u002F1.getting-started",{"title":9,"path":10,"stem":11,"children":12,"page":21},"Setup","\u002Fdocs\u002Fsetup","1.docs\u002F2.setup",[13,17],{"title":14,"path":15,"stem":16},"Domain","\u002Fdocs\u002Fsetup\u002Fdomain","1.docs\u002F2.setup\u002F2.domain",{"title":18,"path":19,"stem":20},"Email","\u002Fdocs\u002Fsetup\u002Faccount","1.docs\u002F2.setup\u002F3.account",false,{"title":23,"path":24,"stem":25},"Email Testing API","\u002Fdocs\u002Fapi","1.docs\u002F3.api",{"title":27,"path":28,"stem":29,"children":30,"page":21},"Features","\u002Fdocs\u002Ffeatures","1.docs\u002F4.features",[31,35,39],{"title":32,"path":33,"stem":34},"Account","\u002Fdocs\u002Ffeatures\u002Faccount","1.docs\u002F4.features\u002F1.account",{"title":36,"path":37,"stem":38},"Mailbox","\u002Fdocs\u002Ffeatures\u002Fmailbox","1.docs\u002F4.features\u002F2.mailbox",{"title":40,"path":41,"stem":42},"Messages","\u002Fdocs\u002Ffeatures\u002Fmessage","1.docs\u002F4.features\u002F3.message",{"title":44,"path":45,"stem":46,"children":47,"page":21},"Guides","\u002Fdocs\u002Fguides","1.docs\u002F5.guides",[48,52,56,60,64,68],{"title":49,"path":50,"stem":51},"CI","\u002Fdocs\u002Fguides\u002Fci","1.docs\u002F5.guides\u002F1.ci",{"title":53,"path":54,"stem":55},"Catch-All","\u002Fdocs\u002Fguides\u002Fcatch-all","1.docs\u002F5.guides\u002F2.catch-all",{"title":57,"path":58,"stem":59},"SPF, DKIM, DMARC","\u002Fdocs\u002Fguides\u002Fspf-dkim-dmarc","1.docs\u002F5.guides\u002F3.spf-dkim-dmarc",{"title":61,"path":62,"stem":63},"E2E Flows","\u002Fdocs\u002Fguides\u002Fe2e","1.docs\u002F5.guides\u002F4.e2e",{"title":65,"path":66,"stem":67},"Email Clients","\u002Fdocs\u002Fguides\u002Femail-clients","1.docs\u002F5.guides\u002F5.email-clients",{"title":69,"path":70,"stem":71},"AI Agents","\u002Fdocs\u002Fguides\u002Fagents","1.docs\u002F5.guides\u002F6.agents",{"id":73,"title":74,"body":75,"description":331,"extension":332,"meta":333,"navigation":334,"path":58,"seo":335,"stem":59,"__hash__":336},"docs\u002F1.docs\u002F5.guides\u002F3.spf-dkim-dmarc.md","Verifying SPF, DKIM, and DMARC in Staging",{"type":76,"value":77,"toc":320},"minimark",[78,87,91,130,134,147,208,216,220,273,277,306,316],[79,80,81,82,86],"p",{},"Every message that arrives ",[83,84,85],"a",{"href":15},"over MX"," is checked against the sender's SPF record, DKIM signature, and DMARC policy. Send from staging to a sandbox address and you get a verdict on your DNS before any real recipient does.",[88,89,9],"h2",{"id":90},"setup",[92,93,95,100,106,110,123,127],"steps",{"level":94},"3",[96,97,99],"h3",{"id":98},"add-a-sandbox-domain-and-point-its-mx-record-at-mxsmtpdev","Add a sandbox domain and point its MX record at mx.smtp.dev",[79,101,102,105],{},[83,103,104],{"href":15},"Domain setup"," has the record.",[96,107,109],{"id":108},"create-a-recipient-account","Create a recipient account",[79,111,112,113,117,118,122],{},"e.g. ",[114,115,116],"code",{},"authcheck@sandbox.example.com"," on the ",[83,119,121],{"href":120},"\u002Faccounts","Accounts"," page.",[96,124,126],{"id":125},"send-to-it-from-your-staging-infrastructure","Send to it from your staging infrastructure",[79,128,129],{},"Through the same provider and DNS your production traffic will use. Authentication checks the path the message took, so it has to actually leave your infrastructure.",[88,131,133],{"id":132},"reading-the-results","Reading the Results",[79,135,136,137,141,142,146],{},"Open the message in ",[83,138,140],{"href":139},"\u002Fmail\u002Faccounts","Mail"," - verification results are shown with the message. Over the API, they're on the ",[83,143,145],{"href":144},"\u002Fdocs\u002Fapi#get-a-message","Message resource",":",[148,149,154],"pre",{"className":150,"code":151,"language":152,"meta":153,"style":153},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","curl \"https:\u002F\u002Fapi.smtp.dev\u002Faccounts\u002F{accountId}\u002Fmailboxes\u002F{mailboxId}\u002Fmessages\u002F{id}\" \\\n  -H \"X-API-KEY: smtplabs_your_api_key_here\" | jq '.verifications'\n","bash","",[114,155,156,180],{"__ignoreMap":153},[157,158,161,165,169,173,176],"span",{"class":159,"line":160},"line",1,[157,162,164],{"class":163},"sBMFI","curl",[157,166,168],{"class":167},"sMK4o"," \"",[157,170,172],{"class":171},"sfazB","https:\u002F\u002Fapi.smtp.dev\u002Faccounts\u002F{accountId}\u002Fmailboxes\u002F{mailboxId}\u002Fmessages\u002F{id}",[157,174,175],{"class":167},"\"",[157,177,179],{"class":178},"sTEyZ"," \\\n",[157,181,183,186,188,191,193,196,199,202,205],{"class":159,"line":182},2,[157,184,185],{"class":171},"  -H",[157,187,168],{"class":167},[157,189,190],{"class":171},"X-API-KEY: smtplabs_your_api_key_here",[157,192,175],{"class":167},[157,194,195],{"class":167}," |",[157,197,198],{"class":163}," jq",[157,200,201],{"class":167}," '",[157,203,204],{"class":171},".verifications",[157,206,207],{"class":167},"'\n",[79,209,210,211,215],{},"For the underlying headers, fetch the ",[83,212,214],{"href":213},"\u002Fdocs\u002Fapi#get-a-message-source","raw source",".",[88,217,219],{"id":218},"what-each-check-means","What Each Check Means",[221,222,223,236],"table",{},[224,225,226],"thead",{},[227,228,229,233],"tr",{},[230,231,232],"th",{},"Check",[230,234,235],{},"Passes when",[237,238,239,248,256],"tbody",{},[227,240,241,245],{},[242,243,244],"td",{},"SPF",[242,246,247],{},"The delivering server's IP is listed in the envelope sender domain's SPF record",[227,249,250,253],{},[242,251,252],{},"DKIM",[242,254,255],{},"The message signature validates against the public key published in the signer's DNS",[227,257,258,261],{},[242,259,260],{},"DMARC",[242,262,263,264,268,269,272],{},"SPF or DKIM passes ",[265,266,267],"strong",{},"and"," the passing domain aligns with the visible ",[114,270,271],{},"From"," domain",[88,274,276],{"id":275},"common-failures","Common Failures",[278,279,280,291,297],"ul",{},[281,282,283,286,287,290],"li",{},[265,284,285],{},"SPF fails after adding a provider",": the provider's ",[114,288,289],{},"include:"," is missing from your SPF record, or the record now exceeds the 10-DNS-lookup limit.",[281,292,293,296],{},[265,294,295],{},"DKIM fails on a fresh setup",": the selector in the signature doesn't match the DNS record name, or the key was rotated and DNS still serves the old one.",[281,298,299,302,303,305],{},[265,300,301],{},"SPF and DKIM pass, DMARC fails",": alignment. The domain that passed isn't the one in ",[114,304,271],{}," - typical when a provider signs with its own domain instead of yours.",[307,308,309],"note",{},[79,310,311,312,315],{},"Mail sent between sandbox accounts through ",[114,313,314],{},"send.smtp.dev"," never crosses your DNS, so it says nothing about your SPF or DKIM. Send from the infrastructure you're validating.",[317,318,319],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":153,"searchDepth":182,"depth":182,"links":321},[322,328,329,330],{"id":90,"depth":182,"text":9,"children":323},[324,326,327],{"id":98,"depth":325,"text":99},3,{"id":108,"depth":325,"text":109},{"id":125,"depth":325,"text":126},{"id":132,"depth":182,"text":133},{"id":218,"depth":182,"text":219},{"id":275,"depth":182,"text":276},"Send from staging to a sandbox address and read the SPF, DKIM, and DMARC results on the received message before you change production DNS.","md",{},{"title":57},{"title":74,"description":331},"EBkg2qysHC9IaQZ6aDYijFdVaTmx_2h2YMR0rZ-3vuc",[338,340],{"title":53,"path":54,"stem":55,"description":339,"children":-1},"A * account catches mail for every address on your domain that has no account of its own. A fresh address per test, no setup per address.",{"title":61,"path":62,"stem":63,"description":341,"children":-1},"A Playwright test that triggers a reset, polls the API for the email, extracts the link, and finishes the flow. Same pattern for signup confirmations.",1786919882657]