Best Practices
Recommended workflows and tips
Email Authentication Best Practices
Follow these guidelines for optimal email deliverability and security.
SPF Best Practices
Use DMARC Busta's managed SPF to consolidate includes and stay within limits.
Email service IPs change. Use include: directives to automatically stay current.
Once your SPF is complete, use -all to reject unauthorized senders.
Circular references (including yourself) waste lookups and can cause failures.
DKIM Best Practices
Every service sending email for you should have DKIM configured.
1024-bit keys are considered weak. Most providers now default to 2048-bit.
Regular key rotation limits exposure if a key is compromised.
DMARC Best Practices
Monitor first to identify all legitimate email sources before enforcing.
Use DMARC Busta's progression system: none → quarantine → reject.
Before quarantine, achieve 95%+ DMARC pass. Before reject, achieve 99%+.
Wait 30 days at each policy level to ensure stability before progressing.
Using Autopilot
For hands-off management, enable Autopilot to let DMARC Busta's AI automatically approve high-confidence sources, monitor DKIM health, and progress your DMARC policy safely based on your domain's volume classification.