Blog article
Phishing, spoofing, and Spam continue to threaten organizations’ reputations and security. To reduce these risks, email authentication protocols such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC) have become essential.
In June 2025, Cloudflare introduced a new requirement for all messages sent through its Email Routing service: They must pass either SPF or DKIM authentication checks by July 3, 2025. Cloudflare also strongly recommends that all senders implement DMARC.
This update reflects a broader industry trend focused on enforcing stricter email authentication policies. The growing adoption is possibly due to the increase in cyberthreats. In 2023, it was reported that cybercrime is expected to cost the world over $23 trillion by 2027.
Before examining Cloudflare’s new policy, it’s important to understand how SPF, DKIM, and DMARC protect domains from abuse.
SPF lets domain owners specify which IP addresses are authorized to send messages on their behalf. When a message arrives, the recipient’s email server checks the sender’s IP address against the SPF record in the DNS. If the IP address is listed, the email passes SPF authentication.
DKIM adds a digital signature to the email header using a private key. The recipient verifies this signature using the public key published in the DNS. DKIM ensures that the email content hasn’t been altered during transit.
DMARC builds on SPF and DKIM by allowing domain owners to publish policies that tell receiving servers how to handle emails that fail authentication. DMARC also provides reporting, giving businesses visibility into how their domains are being used.
DMARC policies can be configured to:
Effective July 3, 2025, Cloudflare requires that all messages sent through its Email Routing platform must pass either SPF or DKIM authentication checks. Emails without SPF and DKIM will be forwarded to upstream mailbox providers. Cloudflare also suggests that every sender configure DMARC.
This change reflects Cloudflare’s commitment to improving email security. It also aligns with the policies of major email providers, including Google, Microsoft, and Yahoo, which already enforce strict authentication requirements to protect users.
The Cloudflare SPF and DKIM requirements aim to:
Simplify compliance with expert support
Navigating email authentication can be complex, but it doesn’t have to be. Sendmarc helps companies streamline SPF, DKIM, and DMARC implementation with expert tools and provides guidance every step of the way.
To prevent email delivery disruptions and maintain secure communication, it’s essential to review and update your organization’s email authentication setup.
Host | Type | Value |
---|---|---|
_dmarc.yourdomain.com | TXT | v=DMARC1; p=reject; rua=mailto:[email protected]; fo=1; |
Host | Type | Value |
---|---|---|
@ | TXT | v=spf1 ip4:192.168.0.1 include:mail.example.com -all |
Host | Type | Value |
---|---|---|
selector._domainkey.yourdomain.com | TXT | v=DKIM1; k=rsa; p=[YourPublicKeyHere] |
At Sendmarc, we simplify the process of DMARC, SPF, and DKIM implementation, allowing you to experience the benefits of advanced email security without the effort.
Email providers are increasingly rejecting unauthenticated messages to protect users from cyberthreats.
By following the Cloudflare DMARC recommendation, you can:
Phishing attacks often impersonate trusted domains to steal credentials or deliver malware. DMARC enforcement blocks unauthorized use of your business’s domain, helping protect its reputation and customers.
Earlier this year, 72% of companies globally reported an increase in cyber risks, showcasing the need for stronger defenses.
Emails that pass SPF, DKIM, and DMARC checks are more likely to reach inboxes, instead of being marked as Spam or Junk.
DMARC reports provide valuable insights into who’s sending emails on your behalf. With this data, you can detect unauthorized senders and take action to prevent abuse.
To meet the Cloudflare DMARC, SPF, and DKIM guidance, follow these best practices:
Often caused by missing or misconfigured SPF or DKIM records. Run an analysis of the headers of the failing emails via our diagnostic tool to identify and resolve issues.
DNS changes can take up to 48 hours to propagate globally. Schedule updates with this delay in mind.
Only one DMARC and one SPF record are allowed per domain. Merge any overlapping configurations to avoid problems.
Act now to secure your email domain
The new Cloudflare SPF and DKIM requirements are a significant advancement in email security. It highlights the increasing importance of email authentication. By configuring and maintaining SPF, DKIM, and DMARC, you can:
Enhance your email security with expert support
Partner with specialists who understand the landscape and can guide you through every step. Sendmarc offers end-to-end DMARC management to help you:
Book a demo with Sendmarc today and take control of your business’s email security.
Latest articles
Dangling DNS: Meaning, risks, & solutions
DMARC protection via Sendmarc & Inter Engineering
Hiring top cybersecurity talent: strategies for success