If someone sends an email that appears to come from your company, can your customers tell it is fake? Without a few settings in your domain's DNS records, probably not. Attackers regularly send messages that spoof a contractor's domain to ask a client to change a payment address or to send invoices to a new account.
Three standards, SPF, DKIM and DMARC, help receiving mail servers decide whether a message is genuinely yours. They are not glamorous, but they protect your reputation and your customers, and they are usually inexpensive to implement.
What Each One Does
SPF: who is allowed to send
Sender Policy Framework is a DNS record that lists the servers authorized to send email for your domain. It might include Microsoft 365, your marketing email service and your accounting platform's notification system. When a receiving server gets a message, it checks whether the sending server is on your list.
DKIM: proof the message was not altered
DomainKeys Identified Mail adds a digital signature to outgoing messages. The signature is tied to a key published in your DNS. A receiving server uses it to confirm that the message really came from your system and was not changed in transit.
DMARC: what to do when checks fail
Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving servers what to do with messages that fail SPF and DKIM: nothing, quarantine them in spam, or reject them. It also sends you reports showing who is sending email using your domain.
Why Contractors Should Care
- Payment fraud: a spoofed message that appears to come from your accounts receivable address can redirect a customer's payment.
- Reputation: if criminals send spam using your domain, legitimate messages to owners and architects may start landing in junk folders.
- Compliance and insurance: cyber insurance applications often ask whether email authentication is in place.
How to Roll It Out Safely
The most common mistake is jumping straight to a strict DMARC policy. If you forget a legitimate sender, such as the system that emails pay applications or the HR platform, those messages will be blocked. Do it in stages.
- Inventory your senders. List every service that sends email using your domain: Microsoft 365, accounting software, project management notifications, marketing tools, ticketing systems, printers and scanners.
- Publish SPF including all legitimate senders. Keep the list tidy, since SPF has limits on how many lookups it allows.
- Enable DKIM in each sending service that supports it, starting with Microsoft 365.
- Publish DMARC in monitoring mode. A policy of "none" with reporting turned on tells you who is sending without blocking anything.
- Review reports for a few weeks. Fix legitimate senders that fail, and identify unknown ones.
- Move to quarantine, and eventually to reject, once reports show your legitimate mail passes consistently.
The reports are technical, so many companies use a reporting service or have their IT provider interpret them.
Common Problems
- Forgotten senders. A marketing platform or a copier that scans to email stops working after enforcement.
- Too many SPF includes. The record exceeds its lookup limit and fails.
- Subdomains. Attackers can spoof subdomains you do not use. DMARC policy can be applied to them too.
- Multiple records. A domain should have only one SPF record. Two conflicting records cause failures.
Beyond Authentication
These standards stop others from impersonating your exact domain. They do not stop lookalike domains, for example one that swaps a letter, or phishing that arrives from a legitimate-looking but different address. Combine them with:
- Email filtering that flags external messages and suspicious links.
- Staff training on payment change requests.
- A rule that banking changes are verified by phone using a number you already have.
- Multi-factor authentication on every mailbox.
Checking Where You Stand
You can check your current records using publicly available lookup tools or ask your IT provider. If there is no DMARC record at all, or it is set to "none" with no one reading the reports, you have room to improve.
Rolling this out for a company with a handful of mail-sending systems usually takes a few weeks of calendar time, mostly spent observing. Ironfield Cyber can inventory your senders, publish the records and manage the move to enforcement so legitimate mail keeps flowing.