Zum Hauptinhalt springen
Support
0
Kontaktieren Sie uns
English
Nederlands
Español
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareers
Cloud Compute

Mit Cloud Compute haben Sie jederzeit und überall Zugriff auf ein Portal, über das Sie Ihre gesamte IT-Umgebung konfigurieren können – egal wo auf der Welt Sie sich befinden.

Cloud-Speicher

Zuverlässiger Zugriff auf Ihre Dateien, Infrastruktur und Anwendungen zu jeder Zeit – ganz ohne Unterbrechungen oder Verzögerungen. Bei Worldstream bieten wir eine Vielzahl von Speicherlösungen an.

Flexible cloud icon
Flexible Cloud
Private cloud icon
Private Cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Objektspeicher
Hollow cube icon
Dateiablage
Block storage icon
Blockspeicher
Backup storage icon
Sicherungsspeicher
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Dedicated Server

Wählen Sie jetzt Ihren Dedicated Server. Individuelle oder Instant Delivery. Leistungsstarke Server, die perfekt zu Ihrem Anwendungsfall passen.

Use Cases

Ganz gleich, welcher Use Case – wir helfen Ihnen, die ideale Lösung zu finden.

Deal servers icon
Deals
AMD servers icon
AMD-Prozessoren
AI servers icon
Intel-Prozessoren
Hollow cube icon
Virtualisierung, Containerisierung & Orchestrierung
Hollow cube icon
Websites & Applications
Hollow cube icon
Gaming & Streaming Infrastruktur
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Smartes Outsourcing

Bestimmte IT-Lösungen generieren Mehrwert, andere erfüllen eher eine unterstützende Funktion. Denken Sie beim Outsourcing daran.

Kosteneffizienz

IT-Komplettpakete mögen erstmal wie eine sichere Option erscheinen, doch wenn man sich die Kosten genau anschaut, sind andere Lösungen oft sinnvoller.

IT-Flexibilität und Kontrolle

Outsourcing heißt nicht, dass man die Kontrolle verliert; man bekommt sogar mehr Flexibilität und Kontrolle.

Cloud-Repatriierung

Die Cloud ist kein Endziel: Sie sollten Ihre Cloud-Umgebung kontinuierlich prüfen und an die sich ändernden Anforderungen anpassen.

Finanzdienstleistungen
Logistik und Transport
Einzelhandel und E-commerce
Medien und Unterhaltung
Technik und Softwareentwicklung
Sicherheit
Managed Service Provider
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Chatten Sie mit unsKontaktieren Sie uns
Über WorldstreamÜber die TechnologieKundenfälleWissensdatenbank
Über unsLernen Sie unser Team kennenJobsWerden Sie WiederverkäuferZertifizierungenUnsere RechenzentrenUnser NetzwerkDDoS-SchutzAMD EPYC-ServerTechnologiepartnerBetriebssystemeAlle KundenfälleEasyTerraDutch Drone CompanyPerfGridArtikelFAQNachrichten und BlogbeiträgeProdukte und Services
Kontaktieren Sie uns

Rufen Sie an unter +31 (0) 174 – 712 117 Industriestraat 53, Naaldwijk

English
Nederlands
Español
0
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareersÜber WorldstreamÜber die TechnologieKundenfälleWissensdatenbankMy Worldstream
Contact
Support
EnglishNederlandsEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Email authentication: SPF, DKIM and DMARC explained

Email authentication: SPF, DKIM and DMARC explained

Gilt für Mail servers you run yourself, general conceptZielgruppe Technical evaluator, domain administratorZuletzt geprüft September 2026

Kort antwoord

SPF, DKIM and DMARC are three DNS-based mechanisms that let receiving mail servers check whether a message claiming to be from your domain is genuine. SPF lists which servers are allowed to send for your domain, DKIM cryptographically signs outgoing mail, and DMARC ties the two together with a policy telling receivers what to do when a check fails. Get all three configured correctly and you cut down both spoofed mail pretending to be you and your own legitimate mail landing in spam.

Auf dieser Seite
  • SPF: who's allowed to send for your domain
  • DKIM: proving the message wasn't altered
  • DMARC: the policy that ties them together
  • Why all three matter together

SPF: who's allowed to send for your domain

SPF, Sender Policy Framework, is a TXT record published in your domain's DNS that lists which mail servers are authorised to send email on behalf of that domain. When a receiving mail server gets a message claiming to be from your domain, it can look up your SPF record and check whether the server that actually sent the message is on the list. If it isn't, that's a signal the message may not be legitimate, and the receiving server can act on that, typically rejecting or flagging it.

SPF only checks the sending server's identity against the list. It doesn't verify anything about the message content, and it doesn't survive certain kinds of forwarding well, which is one of the reasons it's meant to work alongside DKIM rather than alone.

DKIM: proving the message wasn't altered

DKIM, DomainKeys Identified Mail, works differently. Outgoing mail gets a cryptographic signature attached, generated using a private key the sending mail server holds. The corresponding public key is published as a TXT record in DNS. A receiving server can fetch that public key and use it to verify the signature, confirming two things at once: the message really was signed by something holding your domain's private key, and the signed parts of the message weren't altered in transit.

Where SPF checks the sending server, DKIM checks the message itself, and it survives most forwarding scenarios that break SPF, since the signature travels with the message rather than depending on which server relayed it.

DMARC: the policy that ties them together

SPF and DKIM each answer a narrow question, but neither tells a receiving server what to actually do when a check fails, or confirms the domain in the visible "From" address matches what was checked. DMARC is a DNS TXT record that adds that policy layer: it states what a receiving server should do when a message fails SPF, fails DKIM, or fails the alignment check between them, options are typically to do nothing but monitor, quarantine the message (usually meaning spam), or reject it outright. DMARC also specifies where receiving servers should send aggregate reports, which gives the domain owner visibility into who's sending mail using their domain, including any spoofing attempts.

Why all three matter together

These three mechanisms are complementary rather than redundant. SPF alone is easy for an attacker to work around by sending through a completely different mechanism DKIM would catch. DKIM alone doesn't tell a receiver what to do about a failure. DMARC without SPF or DKIM configured underneath it has nothing to actually enforce. Configured together, they give receiving mail servers a reliable way to distinguish genuine mail from your domain from mail that's merely claiming to be.

The practical payoff shows up in two places. First, deliverability: mail providers increasingly weigh SPF, DKIM and DMARC status when deciding whether a message is legitimate, and missing or misconfigured records are a common, avoidable reason legitimate mail ends up in spam. Second, anti-spoofing: a domain with all three correctly configured is significantly harder for someone else to impersonate convincingly in a phishing attempt, since spoofed mail is more likely to fail the checks and get quarantined or rejected before it reaches an inbox.

Related articles

  • DNS record types explained
  • Recognising phishing attempts targeting hosting customers
  • Getting your IP address removed from an email blacklist
War dieser Artikel hilfreich?

Solide IT. Keine Überraschungen

Sparringspartner für IT-Reife
Wir räumen die Hindernisse aus dem Weg, damit Sie freie Bahn haben
Vorhersehbare und transparente Kosten

Kontakt

  • Industriestraat 53, Naaldwijk
  • Zahlungsmöglichkeiten
  • Missbrauch
  • Ressourcen für Entwickler
  • Network Operations Center
  • Über uns
  • Lernen Sie unser Team kennen
  • Jobs
  • Werden Sie Wiederverkäufer
  • Zertifizierungen
  • Unsere Rechenzentren
  • Unser Netzwerk
  • DDoS-Schutz
  • AMD EPYC-Server
  • Technologiepartner
  • Betriebssysteme
  • Übersicht
  • FAQ
  • Kundenfälle
  • Nachrichten und Blogbeiträge
  • Use Cases
English
Nederlands
Español
English
Nederlands
Español
  • Rechtliches
  • Transparenzhinweis