---
title: "The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing! | DuoCircle"
description: "The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!"
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/"
---

Quick Answer

Email authentication evolved over roughly two decades. SPF began as Jim Miller's 1997 idea to verify the SMTP MAIL FROM via DNS, progressed through Bill Cole's 2000 Usenet proposal, David Green's 2002 Mail Transmitter RR draft, Hadmut Danisch's RMX, Gordon Fecyk's DMP, and was published as Sender Permitted From by Meng Weng Wong in June 2003\. Wayne Schlitt added the mx mechanism (Aug 2003) and David Saez added include (Aug 2003). DKIM emerged in 2004 by merging Yahoo's DomainKeys (Mark Delany) with Cisco's Identified Internet Mail (Jim Fenton, Michael Thomas), standardized as RFC 6376\. DMARC, published in 2012 and standardized as RFC 7489 in 2015, ties SPF and DKIM together with alignment checks, a published policy (none, quarantine, reject), and aggregate plus forensic reporting. Together the three protocols verify the sending IP, sign the message body cryptographically, and tell receivers what to do when checks fail.

The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/04/The-Journey-of-SPF-DKIM-and-DMARC.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=The%20Journey%20of%20SPF%2C%20DKIM%2C%20and%20DMARC-%20The%20Three%20Fortifiers%20Against%20Phishing%20and%20Spoofing!&url=undefined%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F&title=The%20Journey%20of%20SPF%2C%20DKIM%2C%20and%20DMARC-%20The%20Three%20Fortifiers%20Against%20Phishing%20and%20Spoofing! "Share on Reddit") [ ](mailto:?subject=The%20Journey%20of%20SPF%2C%20DKIM%2C%20and%20DMARC-%20The%20Three%20Fortifiers%20Against%20Phishing%20and%20Spoofing!&body=Check out this article: undefined%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F "Share via Email") 

![DMARC’s effectiveness](https://media.mailhop.org/duocircle/images/2024/04/dkim-selector-3.jpg) 

[DMARC has already gained the attention](https://www.forbes.com/sites/forbestechcouncil/2023/08/31/strengthening-brand-reputation/) it deserves, owing to its efficiency in combatting phishing and spoofing attacks. But the journey wasn’t fast and steady from the beginning. It all started when SPF came into play, followed by the amalgamation of [Yahoo’s DomainKeys](/email-security/what-is-the-difference-between-domainkeys-and-dkim/) and **Cisco’s Identified Internet Mail (IIM)**. This blog covers the journey of all three email authentication protocols in detail.

## SPF’s Birth

In 2000, experts felt the need for a technology that could identify genuine and **authentic senders** of emails. However, nobody made any significant efforts toward this. But after two years, Dana Valerie Reese came up with an [SPF](/content/spf-record-check)\-like technology while being under the impression that this type of solution had never been discussed before. 

This is how the journey unfolded-

### The First Phase

#### Dec 14, 1997- Ideation

Jim Miller proposed the concept of verifying SMTP **Mail From address** using [outbound SMTP](/content/outbound-smtp) DNS records. 

#### March 27, 2000- Public Mention of the Concept

Bill Cole shared the idea of developing mail **Sender DNS records** on the [Usenet newsgroup](https://en.wikipedia.org/wiki/Usenet%5Fnewsgroup). These records were intended to capture a domain’s outgoing email servers.

#### June 1, 2002- David Green’s Mail Transmitter RR Came into Existence

David Greens published a mail transmitter RR draft with a new DNS type, that was, **MT DNS RR**. His draft was later placed in other IETF drafts.

#### June 2, 2002- Paul Vixie’s Repudiated Mail-From Draft

Paul Vixie came across David Green’s post and sent a draft called “**Repudiating MAIL FROM**” to the mailing list of name droppers. 

#### December 2, 2002- Hadmudt Danish Developed the First RMX Draft

Hadmut Danisch brought forth the primary version of RMX. RMX is a [DNS RR](https://www.tutorialspoint.com/dns-resource-records) for simple SMTP sender authentication. His draft revolved around the then-newest DNS RR type RMX to publish IP4 network block or redirection to the **APL record**. 

#### March 28, 2003- Gordon Fecyk’s First DMP Draft

_Gordon Fecyk developed Version 00, followed by Version 01 and Version 02 of the Designated Sender’s protocols._ These protocols proposed a [DNSBL-like technology](https://inguide.in/what-is-domain-name-system-blacklist-dnsbl/) and permitted the use of **RFC2821 mail-from**. A few years later, Version 03 was also introduced and addressed as **DMP**. 

#### June 10, 2003- SPF-discussion Mail List by Meng Weng Wong

SPF was not a publicly-available technology until 2003\. It was Meng Weng Wong who released the first version of SPF in June 2003\. At that time, SPF stood for **Sender Permitted From** and not Sender Policy Framework.

#### August 18, 2003- Wayne Schlitt’s ‘mx’ Mechanism

Wayne Schlitt proposed the [‘mx’ mechanism](http://www.open-spf.org/Mechanism/mx/), which tells **which email servers will be used** when an email is relayed.

#### August 19, 2003- David Saez’s ‘spf include’ Operation

_David Saez introduced the **‘include’ mechanism**, which allows domain owners to add email-sending sources of [third-party vendors](https://www.ncontracts.com/nsight-blog/what-is-a-third-party-vendor) that send emails on their behalf._

#### October 1, 2003- Beginning of the ASRG Mail From

SPF was merged into a s**ingle proposal** for checking [Mail From](https://wordtothewise.com/2015/05/what-is-the-mail-from-field/).

#### October 8, 2003- Change of DNS Type

_It was Paul Wouters who **suggested replacing** the inefficient TXT record type with the DNS RR type._ Parallely, Meng also encouraged the same.

#### October 10, 2003- Introduction of the v=spf1 Version

Meng Weng Wong published proper **SPF rules** for open discussions. 

### The Second Phase

The next important stage was the introduction of **Sender ID**, which was achieved by combining SPF with [Microsoft’s Caller ID for emails](https://www.itprotoday.com/email-and-calendaring/microsoft-plans-email-caller-id-standard#close-modal). However, the concept faced licensing challenges, resulting in a conflict in the industry. Many organizations chose to support SPF independently, holding a significant juncture in SPF’s journey.

Even after the obstacles, SPF didn’t lose its worth; it was just a matter of time and a **few alterations** that made SPF a fortifier against phishing and spoofing.

## DKIM’s Birth

[![phishing attacks](https://media.mailhop.org/duocircle/images/2024/04/SMTP-relay-5713.jpg)](https://media.mailhop.org/duocircle/images/2024/04/SMTP-relay-5713.jpg)

[DKIM](/resources/what-is-dkim) came after SPF’s development, as a protocol that could effectively handle forwarded emails and verify the **integrity of message content** during transit. _The DKIM protocol is the amalgamation of Cisco’s Identified Internet Mail (IIM) and Yahoo’s DomainKeys, hence the name DomainKeys Identified Mail._ 

Cisco’s IIM enhances outgoing emails with cryptographic signatures, ensuring they originate from authorized and legitimate sources. This process serves as a defense against [malicious actors](https://www.hipaajournal.com/malicious-actors-increasingly-targeting-cloud-services-in-healthcare-cyberattacks/) attempting to infiltrate a company’s email system and launch [phishing attacks](https://edition.cnn.com/politics/online-scams-fbi/index.html). _Verification occurs at the **receiver’s end** and involves Mail Transfer Agents (MTAs) or Mail User Agents (MUAs)._

Meanwhile, Yahoo’s DomainKeys focuses on verifying that a message’s content remains **unaltered during transit**. It employs a rapid binary assessment method, swiftly determining whether emails should be directed to the inbox or spam folder based on signatures and an original pair of [public and private keys](https://www.appviewx.com/education-center/what-are-public-and-private-keys/).

**Early adopters of DKIM** included [Gmail](/email-services/gmail-550-5-7-26-error-for-emails-failing-dmarc-checks/), Fastmail, AOL, and Yahoo, and usage rapidly expanded over time.

## DMARC’s Birth

DMARC’s development was first discussed in 2010 as the users and industry experts came across the **shortcomings of SPF and DKIM**. So, 15 prominent tech companies came together and collaboratively addressed the problem by pooling their expertise and resources toward the creation of an [email authentication](/resources/email-authentication) protocol that could overcome the shortcomings of SPF and DKIM. In fact, tech giants like PayPal, Microsoft, Yahoo, and Google were also involved. 

[![DMARC](https://media.mailhop.org/duocircle/images/2024/04/what-is-dkim-selector.jpg)](https://media.mailhop.org/duocircle/images/2024/04/what-is-dkim-selector.jpg)

_The main aim was to give recipients’ mail servers the power to provide **feedback to senders’ domains** regarding the authentication status of received messages_. This feedback mechanism now enables senders to refine and enhance their [email security](/content/email-security-services) practices. The initial specification of DMARC was released on January 30th, 2012.

There was never a doubt about DMARC’s effectiveness; however, its adoption was a bit slow at the start. It wasn’t propagated properly, which is why many IT and [cybersecurity](/) professionals remained unaware of its existence, contributing to its limited uptake.

However, **notable developments** occurred in 2015 and 2016 when tech giants like Google and Yahoo implemented stringent email security policies, including the incorporation of [DMARC](/email/dmarc). These actions were intended to incentivize businesses to deploy comprehensive email authentication protocols.

After 2018, private companies were ahead of government bodies in **DMARC adoption**. However, significant progress has been made in recent years. Notably, in the UK, it has become [mandatory for all government services](https://dmarc.org/2016/06/dmarc-required-for-uk-government-services-by-october-1st/) to adhere to [DMARC compliance](https://www.afaqs.com/news/digital/google-and-yahoo-to-enforce-stricter-email-guidelines-indian-marketers-prepare-for-compliance).

Starting in February 2024, [Google and Yahoo](https://www.entrepreneur.com/growing-a-business/3-email-changes-google-and-yahoo-will-require-you-to-adopt/467973) have mandated DMARC for **bulk and regular senders** under different specifications and conditions. This requirement is expected to revolutionize the email authentication journey.

## Topics

DMARCemail securitySecurity 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F) [ ](https://twitter.com/intent/tweet?text=The%20Journey%20of%20SPF%2C%20DKIM%2C%20and%20DMARC-%20The%20Three%20Fortifiers%20Against%20Phishing%20and%20Spoofing!&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdmarc%2Fjourney-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing%2F) Copy 

Related Articles

- [ ![BIMI](https://media.mailhop.org/duocircle/images/2025/06/spf-permerror-0123.jpg)  Avoiding common BIMI pitfalls: What goes wrong and how to fix it DMARC ](/blog/dmarc/avoiding-bimi-pitfalls-common-errors-and-how-to-fix-them/)
- [ ![Can threat actors bypass DMARC](https://media.mailhop.org/duocircle/images/2025/02/dmarc-generator-7302.jpg)  Can threat actors bypass DMARC? DMARC ](/blog/dmarc/can-threat-actors-bypass-dmarc/)
- [ ![SPF, DKIM, and DMARC requirements](https://media.mailhop.org/duocircle/images/2025/07/sendgrid-alternative-8960.jpg)  Cloudflare’s new SPF, DKIM, and DMARC requirements DMARC ](/blog/dmarc/cloudflares-new-spf-dkim-and-dmarc-requirements/)
- [ ![Deploying DMARC](https://media.mailhop.org/duocircle/images/2026/02/spf-record-7890.jpg)  Deploying DMARC the right way: Here’s what MSPs and enterprises should know DMARC ](/blog/dmarc/deploying-dmarc-correctly-what-msps-and-enterprises-must-know/)

## Related Articles

[  DMARC 6m  Avoiding common BIMI pitfalls: What goes wrong and how to fix it  Jun 24, 2025 ](/blog/dmarc/avoiding-bimi-pitfalls-common-errors-and-how-to-fix-them/)[  DMARC 3m  Can threat actors bypass DMARC?  Feb 21, 2025 ](/blog/dmarc/can-threat-actors-bypass-dmarc/)[  DMARC 7m  Cloudflare’s new SPF, DKIM, and DMARC requirements  Jul 18, 2025 ](/blog/dmarc/cloudflares-new-spf-dkim-and-dmarc-requirements/)[  DMARC 6m  Deploying DMARC the right way: Here’s what MSPs and enterprises should know  Feb 26, 2026 ](/blog/dmarc/deploying-dmarc-correctly-what-msps-and-enterprises-must-know/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","description":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","url":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/","datePublished":"2024-04-12T17:36:29.000Z","dateModified":"2025-08-20T19:33:22.000Z","dateCreated":"2024-04-12T17:36:29.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/"},"articleSection":"dmarc","keywords":"DMARC, email security, Security","wordCount":1047,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/04/dkim-selector-3.jpg","caption":"DMARC’s effectiveness","width":900,"height":504},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"DMARC"},{"@type":"ListItem","position":3,"name":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","item":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"DMARC","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","item":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","description":"The Journey of SPF, DKIM, and DMARC- The Three Fortifiers Against Phishing and Spoofing!","url":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/","datePublished":"2024-04-12T17:36:29.000Z","dateModified":"2025-08-20T19:33:22.000Z","dateCreated":"2024-04-12T17:36:29.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/dmarc/journey-of-spf-dkim-dmarc-fortifiers-against-phishing-and-spoofing/"},"articleSection":"dmarc","keywords":"DMARC, email security, Security","wordCount":1047,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/04/dkim-selector-3.jpg","caption":"DMARC’s effectiveness","width":900,"height":504},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
