The three records, and what each proves
SPF lists which servers are allowed to send mail for your domain. Without it, anyone can claim to be you and receiving servers have no way to tell.
DKIM signs each message cryptographically, so the receiver can verify it really came from you and was not altered on the way.
DMARC ties the two together and tells receivers what to do when a message fails: nothing, quarantine it, or reject it outright. Without DMARC, SPF and DKIM failures are advisory and largely ignored.
The mistakes that quietly cost you
Two SPF records. The specification allows exactly one. A second record — usually added when a new mail service is set up — makes SPF fail entirely rather than combine. Merge them into a single record.
More than ten DNS lookups in SPF. Each include: costs a lookup, and nested includes count too. Over ten and the whole record is treated as a permanent error. Large providers routinely push domains over the limit.
DMARC left at p=none. This is monitor-only. It reports failures and asks receivers to do nothing about them. It is the correct starting point and a poor permanent state.
Ending SPF with +all. This authorises every server on the internet to send as you, which is worse than having no record at all. It should be -all or ~all.
The order to fix them in
Start with SPF, because it is the most often broken and the easiest to verify. Then DKIM, which your mail provider generates for you. Then DMARC at p=none so you can watch the reports before enforcing anything.
Only once the reports are clean should you move DMARC to quarantine and then reject. Enforcing before your own legitimate mail passes is how companies accidentally block their own invoices.
Common questions
How long do DNS changes take to affect email?
Usually minutes to a few hours, governed by the TTL on the record. Lower the TTL before making changes if you need them to take effect quickly.
Can I have two SPF records?
No. The specification permits exactly one TXT record starting with v=spf1. A second one causes a permanent error and SPF fails completely. Multiple senders go into a single record as separate include: entries.
What should my DMARC policy be?
Start at p=none to collect reports without affecting delivery. Once your legitimate mail passes SPF or DKIM consistently, move to p=quarantine, then p=reject. Going straight to reject risks blocking your own mail.