DNS & Email Authentication
The authority hub for DNS fundamentals and email authentication — SPF, DKIM, DMARC, DNSSEC, and CAA, connected directly to IT KORR's diagnostic tools.
Tools
DNS & Email Authentication Tools
Free, client-side tools — nothing is transmitted or stored.
SPF / DKIM / DMARC Checker
Recursive SPF dependency analysis, DKIM key strength detection, and full DMARC tag parsing.
Open →
DNS Health Checker
Full DNS diagnostic including MX, NS, and broader record configuration.
Open →
Email Security Analyzer
Broader email-domain security review including BIMI, MTA-STS, and TLS-RPT.
Open →
Foundations
DNS and Email Authentication Architecture
How DNS resolution works, and how SPF, DKIM, and DMARC relate to each other as one system.
DNS Fundamentals for Business IT
Authoritative vs. recursive DNS, record types, delegation, and TTL — the operational concepts that matter when something breaks, not just how DNS works in theory.
Beginner
Open →
Email Authentication Architecture: How SPF, DKIM, and DMARC Work Together
Why SPF and DKIM alone do not protect a domain, what "alignment" actually means, and the decision flow a receiving mail server follows.
Beginner
Open →
Configuration
SPF, DKIM, and DMARC Configuration
Standard-by-standard configuration, troubleshooting, and enforcement guidance.
SPF Configuration and Troubleshooting
Mechanisms, includes, redirects, the all qualifier, multiple-SPF-record conflicts, and the 10-lookup DNS limit that silently breaks otherwise-correct records.
Intermediate
Open →
DKIM Configuration and Troubleshooting
Selectors, key rotation, DNS publication vs. signing, and why "selector not found" does not automatically mean DKIM is unconfigured.
Intermediate
Open →
DMARC Policy and Reporting
Policy enforcement levels, alignment modes, aggregate and forensic reporting, and the safe monitor-to-enforcement progression.
Intermediate
Open →
Quick Reference
The Short Version
Full treatment lives in the articles above.
Authenticated ≠ Aligned
SPF and DKIM can both pass while DMARC still fails, if neither authenticated domain aligns with the visible From address.
+all Is Not a Relaxed SPF Setting
It authorizes any server to send as your domain — functionally equivalent to having no SPF protection at all.
"Selector Not Found" Does Not Mean DKIM Is Unconfigured
Selectors are provider-assigned and non-standard. A missing common-selector result can simply mean the wrong selector was checked.
Never Jump Straight to p=reject
Monitor first, identify every legitimate sender from real aggregate reports, then step enforcement up gradually.
FAQ
Common Questions
How does this cluster relate to DNS, DHCP, and IPAM in the Infrastructure & Networking cluster?
That article covers DNS as one of three core network services (alongside DHCP and IP address management) and how losing any one of them affects a network. This cluster covers DNS authority/resolution and email authentication specifically — the topics a domain-security or email-deliverability assessment actually needs.
Do I need to read these articles in order?
Start with DNS Fundamentals if DNS concepts themselves are unfamiliar, or Email Authentication Architecture if you already understand DNS and want the SPF/DKIM/DMARC relationship specifically. The SPF, DKIM, and DMARC articles are each self-contained references you can jump to directly from a specific diagnostic finding.
Why does IT KORR distinguish between DNSSEC detection and DNSSEC validation?
A DNS lookup finding a DNSKEY or DS record present confirms DNSSEC signing appears configured — it is not the same as fully validating the cryptographic chain of trust. Overstating one as the other misrepresents the actual assurance a finding provides.
Related Resources
Continue Into a Related Cluster
Infrastructure & Networking
DNS as a core network service (alongside DHCP and IPAM), plus the broader network architecture this cluster's content assumes.
Open →
Microsoft 365 Security & Entra ID
Email authentication is frequently a Microsoft 365 tenant configuration question — see the broader tenant security guidance here.
Open →
Compliance & Governance
DMARC enforcement is a documented control in several compliance frameworks — see how it fits into a broader governance program.
Open →
Operational Support
Need help configuring or enforcing email authentication?
IT KORR can audit your current DNS and email authentication posture and coordinate SPF, DKIM, and DMARC implementation across your current providers — no migration required.
No commitment required — we respond within one business day.