By J. Mesa
Anyone can send an email that claims to come from your business address. The original design of email never checked. Criminals use that gap to send fake invoices to your customers in your name. Three DNS records close it: SPF, DKIM, and DMARC. Since February 2024, Google and Yahoo have required them from bulk senders, and mail from domains without them lands in spam more often each month.
What is email spoofing?
Email spoofing is forging the “From” address of a message so that it appears to come from someone else. A spoofed message from your domain needs no access to your mailbox. The sender simply types your address into the From line.
What is SPF?
SPF, or Sender Policy Framework, is a DNS record that lists the servers allowed to send email for your domain. When a message arrives, the receiving server checks whether it came from a server on your list.
An SPF record for a business that sends through Microsoft 365 looks like this:
v=spf1 include:spf.protection.outlook.com -all
The ending matters. “-all” tells receivers to reject senders that are not listed. “~all” tells them to treat such mail as suspicious. A domain can have only one SPF record, and that record may trigger no more than ten DNS lookups, so adding every service you have ever tried will break it.
What is DKIM?
DKIM, or DomainKeys Identified Mail, adds a digital signature to each message you send. Your mail system signs the message with a private key. You publish the matching public key in DNS. The receiving server uses it to confirm that the message came from your domain and that nobody altered it on the way.
DKIM survives forwarding better than SPF does, which is one reason you need both.
What is DMARC?
DMARC, or Domain-based Message Authentication, Reporting, and Conformance, ties the other two together. It does three jobs.
- Alignment. It checks that the domain in the visible From address matches the domain that passed SPF or DKIM. Without this check, a criminal could pass SPF with their own domain while showing yours to the reader.
- Policy. It tells receiving servers what to do with mail that fails: nothing, quarantine it, or reject it.
- Reporting. It asks receivers to send you reports of who is sending mail in your domain’s name.
A starting DMARC record looks like this:
v=DMARC1; p=none; rua=mailto:[email protected]
What do the DMARC policies mean?
- p=none. Monitor only. Receivers deliver failing mail as usual and send you reports. This protects nobody, and it is the right place to begin.
- p=quarantine. Receivers send failing mail to the spam folder.
- p=reject. Receivers refuse failing mail outright. This is the goal.
What do Google and Yahoo require?
Since February 2024:
- All senders to Gmail and Yahoo addresses need SPF or DKIM.
- Bulk senders, which Google defines as those sending about 5,000 or more messages a day to Gmail accounts, need SPF, DKIM, and a DMARC record with a policy of at least p=none. Marketing messages need a one-click unsubscribe, and spam complaint rates must stay low.
A small business sending a few hundred messages a day is not a bulk sender. The direction is still clear. Unauthenticated mail is getting filtered, and your invoices and appointment reminders are not exempt.
How do I set up SPF, DKIM, and DMARC?
- List every system that sends email as your domain. Your mail provider, your website’s contact form, your invoicing or accounting software, your newsletter service, your scheduling tool, your CRM, the office copier that scans to email.
- Publish one SPF record that includes each legitimate sender.
- Turn on DKIM in each sending service. Each one gives you DNS records to add. In Microsoft 365 and Google Workspace, DKIM for your own domain is off until you enable it.
- Publish a DMARC record at p=none with a reporting address.
- Read the reports for two to four weeks. They arrive as data files that are hard to read by hand. A DMARC reporting service, several of which offer free tiers, turns them into a chart of who is sending as you.
- Fix what you find. Add the legitimate senders you forgot. Note the ones you do not recognize.
- Move to p=quarantine, then watch for a few more weeks.
- Move to p=reject.
You make these changes wherever your DNS is hosted: your domain registrar, your web host, or a DNS provider.
How do I check my domain?
Free lookup tools from MXToolbox, dmarcian, and others show your current records. You can also send a message to a Gmail account, open it, and choose “Show original.” Gmail displays a pass or fail result for SPF, DKIM, and DMARC.
What are the common mistakes?
- Staying at p=none forever. Monitoring mode stops no spoofed mail. Many businesses publish the record to satisfy a checklist and never move on.
- Two SPF records. That counts as an error, and SPF fails.
- Too many lookups in the SPF record.
- Ending SPF with “+all,” which authorizes the entire internet.
- Forgetting a sender. The invoicing system gets left out, and customer invoices go to spam once enforcement begins.
- Skipping DKIM on third-party services.
- Jumping to p=reject without reading the reports first.
- Ignoring domains you own and do not use for email. Criminals spoof those too. Publish “v=spf1 -all” and a DMARC record of p=reject on each parked domain.
Does DMARC stop all phishing?
No. DMARC stops exact spoofing of your domain. It does not stop:
- Look-alike domains, such as a version of your name with one letter changed
- Display name tricks, where the name shows your boss and the address belongs to a free mail account
- A hacked mailbox, which sends real, authenticated mail. See how to tell if your email has been hacked.
You still need mail filtering, multi-factor authentication, a payment verification procedure, and trained staff who can spot a phishing email.
Why should a small business bother?
- Protection for your customers and vendors. A fake invoice from your address damages your name even though you did nothing.
- Deliverability. Authenticated mail reaches the inbox more reliably.
- Compliance and insurance. PCI DSS version 4 calls for anti-phishing controls, and insurance applications ask about email authentication.
- Visibility. The reports show you every service sending mail as your company, including ones nobody remembers setting up.
How long does it take?
The DNS changes take an hour. Reaching p=reject safely takes four to eight weeks for most small businesses, because you need time to see all your legitimate senders in the reports.
What comes after DMARC?
Two optional additions. MTA-STS tells other servers to deliver mail to you only over an encrypted connection. BIMI displays your logo next to authenticated messages in some inboxes and requires a DMARC policy of quarantine or reject first. Both help. Neither matters until the first three records are in place and enforced.
Your next step
Look up your domain’s DMARC record today. If you find none, or you find p=none with no plan to move forward, start with step 1 above. Cerberus Cybersecurity checks email authentication as part of our risk and compliance assessments and guides small businesses to an enforced policy without losing legitimate mail. Contact us to get started.