Four records, four different jobs
SPF lists which sending systems are allowed to send mail for a domain. DKIM adds a cryptographic signature that receivers can verify with a public key in DNS. DMARC tells receivers how to evaluate SPF/DKIM alignment and where to send reports. CAA is unrelated to mail authentication: it limits which certificate authorities may issue TLS certificates for a domain.
A practical order
- Inventory every legitimate mail sender before tightening SPF.
- Enable DKIM in each sending service and publish its selector records.
- Start DMARC with monitoring, read aggregate reports, then tighten policy gradually.
- Use CAA only after confirming which certificate authorities your hosting/CDN uses.
Common mistakes
Publishing multiple SPF records, rejecting mail before all senders are aligned, and adding a restrictive CAA record without accounting for a CDN or managed host are common failure modes. DNS syntax is only one part of the job; the live behavior still needs verification.