Skip to main content
IT KORR
IT KORRKeeping Organizations Reliable & Resilient
Knowledge Center · Networking

DNS & Email Authentication

The authority hub for DNS fundamentals and email authentication — SPF, DKIM, DMARC, DNSSEC, and CAA, connected directly to IT KORR's diagnostic tools.

Sender

Message sent from your domain

SPF Check

Is the sending IP authorized?

DKIM Check

Is the signature valid?

DMARC Alignment

Does SPF or DKIM align with the From domain?

Receiving System

Applies your DMARC policy: none, quarantine, or reject

Authenticated ≠ AlignedSPF/DKIM can both pass and DMARC can still fail if neither aligns with the visible From domain.
SPF and DKIM are checked independently. DMARC then evaluates whether either one aligns with the visible From address — alignment, not just a pass/fail on SPF or DKIM alone, is what actually determines the outcome.

Start Here

DNS Fundamentals for Business IT

Start here if DNS concepts themselves — not just SPF/DKIM/DMARC — are unfamiliar.

Read now

Quick Reference

The Short Version

Full treatment lives in the articles above.

Authenticated ≠ Aligned

SPF and DKIM can both pass while DMARC still fails, if neither authenticated domain aligns with the visible From address.

+all Is Not a Relaxed SPF Setting

It authorizes any server to send as your domain — functionally equivalent to having no SPF protection at all.

"Selector Not Found" Does Not Mean DKIM Is Unconfigured

Selectors are provider-assigned and non-standard. A missing common-selector result can simply mean the wrong selector was checked.

Never Jump Straight to p=reject

Monitor first, identify every legitimate sender from real aggregate reports, then step enforcement up gradually.

FAQ

Common Questions

How does this cluster relate to DNS, DHCP, and IPAM in the Infrastructure & Networking cluster?

That article covers DNS as one of three core network services (alongside DHCP and IP address management) and how losing any one of them affects a network. This cluster covers DNS authority/resolution and email authentication specifically — the topics a domain-security or email-deliverability assessment actually needs.

Do I need to read these articles in order?

Start with DNS Fundamentals if DNS concepts themselves are unfamiliar, or Email Authentication Architecture if you already understand DNS and want the SPF/DKIM/DMARC relationship specifically. The SPF, DKIM, and DMARC articles are each self-contained references you can jump to directly from a specific diagnostic finding.

Why does IT KORR distinguish between DNSSEC detection and DNSSEC validation?

A DNS lookup finding a DNSKEY or DS record present confirms DNSSEC signing appears configured — it is not the same as fully validating the cryptographic chain of trust. Overstating one as the other misrepresents the actual assurance a finding provides.

Operational Support

Need help configuring or enforcing email authentication?

IT KORR can audit your current DNS and email authentication posture and coordinate SPF, DKIM, and DMARC implementation across your current providers — no migration required.

No commitment required — we respond within one business day.

Build: 7b54ed9 | Built: Jul 21, 2026 9:32 PM EDT