Email was designed without any way to prove who sent a message. Unless you say otherwise, anyone can send mail that appears to come from your domain: an invoice "from accounts", a password reset "from IT". Three DNS records close that gap. They are free, and they are one of the cheapest security fixes a business can make.
SPF: who is allowed to send
SPF is a list, published in your DNS, of the servers allowed to send email for your domain. A receiving mail server checks whether the message came from a server on the list.
The usual mistakes are leaving a service off the list (your invoicing tool, your newsletter provider), publishing
two SPF records when only one is allowed, and ending the record with +all, which tells the world that
every server is permitted.
DKIM: proof the message was not altered
DKIM adds a cryptographic signature to each message you send. The matching public key sits in your DNS, so a receiver can confirm the message really came through your mail system and was not changed on the way. You switch it on in your mail provider's settings and publish the key they give you. Each service that sends for you needs its own.
DMARC: what to do when the checks fail
SPF and DKIM on their own only produce a pass or a fail. DMARC is the instruction that tells receiving servers what to do with a failure, and it asks them to send you reports. It has three settings.
p=none: deliver everything, but send me reports. This is monitoring only.p=quarantine: put failing messages in the spam folder.p=reject: refuse failing messages outright.
The safe order to turn them on
- List everything that sends email as your domain: your mailboxes, plus any billing, booking, marketing, or support tools.
- Publish one SPF record covering all of them, and turn on DKIM for each.
- Publish DMARC at
p=noneand read the reports for a few weeks. They show who is sending as you, including services you forgot. - Once the legitimate senders all pass, move to
p=quarantine, then top=reject.
Skipping step three is how businesses break their own email. Going straight to p=reject with a
forgotten sender means real invoices and appointment reminders vanish without anyone being told.
What these records do not do
They stop other people sending as your exact domain. They do not stop a lookalike domain with one letter changed, and they do not stop phishing sent to your staff from someone else's address. Filtering and staff awareness cover those. But a domain with no DMARC policy is an open invitation, and it is the first thing we check.