Email spoofing: protect your domain with SPF, DKIM and DMARC
Attackers can send emails that look like they come from your company. Three DNS records make that much harder.
Spoofing means someone sends email using your domain name without access to your mailboxes. Clients and suppliers receive what looks like a real invoice or payment request from you.
The three records that stop it
- SPF lists the servers allowed to send email for your domain.
- DKIM adds a cryptographic signature that proves a message was not altered.
- DMARC tells receiving servers what to do when SPF or DKIM fail, and sends you reports.
Roll out in stages
Start DMARC in monitoring mode (p=none), read the reports for two to four weeks to find every legitimate sender, then move to quarantine and finally reject. Going straight to reject can block your own invoices or newsletters.
We configure these records when we set up business email, and audit existing domains as part of our IT security service.