SPF, DKIM and DMARC are small records that live in your domain's DNS. Together they tell the world's mail servers that email claiming to be from your domain is really from you. Modern inbox providers (Gmail, Outlook, Yahoo and the rest) increasingly require them, so getting them right is what stands between the inbox and the spam folder.
SPF, who is allowed to send
SPF (Sender Policy Framework) lists which mail servers are permitted to send email for your domain. When a message arrives, the receiving server checks that it came from a server on your approved list. One important detail: SPF checks the behind-the-scenes “return address” of the message, not the from address your customer sees.
DKIM, a tamper-proof signature
DKIM (DomainKeys Identified Mail) adds an invisible cryptographic signature to every message. The receiving server uses a key published in your DNS to confirm the message really came from your domain and was not altered or forged along the way.
DMARC, your policy and your reports
DMARC ties the first two together. It tells receiving servers what to do with a message that fails SPF and DKIM, and it can send you reports about who is sending mail using your domain. We recommend starting with a monitoring policy (p=none): nothing is blocked, but you build up a clear picture of your email first. A stricter policy can come later once you are confident everything legitimate is passing.
The good news
For the email your store sends, we handle SPF and DKIM through our delivery service, and we can set all three up for you when we manage your DNS. You mainly need to understand what they are so the setup steps in the other articles make sense.