Both Records Passed.
The Domain Still Got Spoofed.
How to construct and read the actual DNS TXT records: SPF mechanisms and qualifiers, DKIM key syntax, and the DMARC alignment rules that decide whether a passing SPF and a passing DKIM actually stop spoofing. Distinct from MAILSCOPE, which analyzes these records against live headers rather than teaching the syntax itself; see the BEC & Phishing Response playbook for what to do when one of these checks fails.
Record Anatomy
Three TXT records, three different purposes: who can send, how to verify the message wasn't altered, and what to do when the first two disagree.
SPF, DKIM, DMARC — Real Syntax
SPF (TXT record on the sending domain) v=spf1 ip4:203.0.113.0/24 include:_spf.google.com -all ├── v=spf1 — protocol version, always required first ├── mechanisms (ip4/ip6/a/mx/include) — what sources are authorized to send └── qualifier + all — the catch-all: -all (fail, strict), ~all (softfail), ?all (neutral), +all (pass, avoid) DKIM (TXT record at selector._domainkey.domain.com) v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC... ├── v=DKIM1 — version ├── k=rsa — key type └── p= — the public key itself, base64-encoded; the matching private key signs outgoing mail DMARC (TXT record at _dmarc.domain.com) v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@domain.com; pct=100; adkim=s; aspf=r ├── v=DMARC1 — version ├── p= — policy: none (monitor only), quarantine (spam folder), reject (block outright) ├── rua= — aggregate report destination, where XML summaries get sent daily └── adkim / aspf — alignment mode: s (strict, exact domain match) or r (relaxed, subdomain allowed)
SPF Mechanisms & Qualifiers
What each piece of an SPF record actually authorizes.
include:
a / mx
ip4 / ip6
~all vs -all
~all (softfail) marks unauthorized senders as suspicious but usually still delivers the message. -all (fail) is the hard stance that should back a mature deployment once false positives are ruled out.DMARC Alignment Rules
Alignment is the piece that actually stops spoofing. SPF and DKIM alone don't.
Strict (s)
Relaxed (r)
DMARC Passes On Either Check
The Classic Spoofing Case
Common Pitfalls
Records that look correct on inspection but don't actually protect the domain.
The 10 DNS Lookup Limit
p=none Doing Nothing But Monitoring
p=none generates reports but enforces nothing. It's a reasonable first step, not a finished deployment, and plenty of domains stop there indefinitely.