SPF, DKIM and DMARC explained: how to stop fraudsters emailing in your name
Without DMARC enforcement, anyone can send email that appears to come from your domain. What SPF, DKIM and DMARC do, and how to introduce them safely.
By Limburg Cyber Group
A client receives an invoice from your email address, with your name and logo, but a different bank account number. You never sent it. That a sender can be forged so easily comes down to how email has worked for decades: the sender address is as easy to fill in as the return address on an envelope. Three settings on your domain name put a stop to it: SPF, DKIM and DMARC.
Why email is so easy to forge
Email was originally designed without any check on who the sender is. Any mail server can send a message with “from: director@yourcompany.com” at the top. Forging a sender like this is called spoofing. A receiving server can only reject such mail if you, as the domain owner, have published in advance who may send email on your behalf, and what should happen to mail that does not meet those rules. You publish this in DNS, the public address book for your domain.
What the three abbreviations do
- SPF is a list of servers allowed to send email for your domain: your own mail provider, but also, for example, your accounting package or newsletter service. The recipient checks whether a message came from one of those servers.
- DKIM puts a digital signature on every outgoing email. The matching key is published in your DNS, so the recipient can verify that the message really came from your domain and was not altered along the way.
- DMARC brings the two together. It checks whether the sender address the recipient sees matches what SPF or DKIM approved. And it tells the recipient what to do if it does not. It also lets you receive reports on who is sending email in your domain’s name.
The important caveat: SPF and DKIM on their own are not enough. SPF looks at a technical sender address the recipient never sees, not at the address in the “from” field. Only DMARC with an enforcing policy ensures that forged mail using your domain is stopped. If DMARC is missing, or set to “do nothing”, your domain can still be spoofed.
A safe rollout in three steps
Do not switch DMARC to its strictest setting in one go. There are often services sending mail on your behalf that are not yet covered by SPF or DKIM, and your own legitimate mail would then be rejected too. The usual route:
- p=none, with reports. DMARC is on but does not yet intervene. You receive reports on all mail sent in your domain’s name. That is how you find the forgotten invoicing module or the printer that emails scans.
- p=quarantine. Once all legitimate mail checks out, you ask recipients to put mail that fails into the spam folder. Keep an eye on the reports.
- p=reject. The end state: forged mail is refused and never arrives.
The reports are technical files; there are services that turn them into a readable overview. Domains you own but do not use for email can be set straight away so that all mail claiming to come from them is rejected.
Large mailbox providers now expect it
Large mailbox providers, such as Google and Yahoo, now expect organisations that send a lot of email to authenticate it with SPF, DKIM and DMARC. If you send newsletters or many invoices by email, a correct setup also helps your mail land in the inbox rather than the spam folder.
What it does not solve
DMARC protects your own domain. It does not stop fraudsters registering a domain that looks like yours, with an extra letter or a different extension. That still calls for vigilance, see spotting phishing and CEO fraud and invoice fraud.
What to ask your IT partner or mail provider
- Are all services that send email on our behalf included in our SPF record?
- Do all of those services sign their mail with DKIM for our own domain?
- Which DMARC policy do we have now, and who reads the reports?
- What is the plan for moving to quarantine and then to reject?
- How are our unused domains set up?
Start with a quick check
Our free email spoofing check shows you straight away how SPF, DMARC and DKIM are currently set up for your domain. Would you like help moving to an enforcing policy without blocking your own mail? See our cybersecurity service or get in touch.
Read more
Passkeys for your business: logging in without a password, and hard to phish
Passkeys replace the password with a key on your device that will not work on a fake site. What they are, what to watch for and how to start sensibly.
Securing your company website: the maintenance nobody gets round to
Many small business websites run for years without maintenance. What to sort out: updates, admin accounts, tested backups, HTTPS and access to your domain.
QR code phishing: how quishing works and how your team can spot it
Scammers hide links in QR codes: in emails, PDFs, letters and on stickers. Why it works, how to recognise it, and what to tell your employees about it.