Email was designed without any way to prove who sent a message. Unless you say otherwise, anyone can send mail that appears to come from your domain: an invoice "from accounts", a password reset "from IT". Three DNS records close that gap. They are free, and they are one of the cheapest security fixes a business can make.

SPF: who is allowed to send

SPF is a list, published in your DNS, of the servers allowed to send email for your domain. A receiving mail server checks whether the message came from a server on the list.

The usual mistakes are leaving a service off the list (your invoicing tool, your newsletter provider), publishing two SPF records when only one is allowed, and ending the record with +all, which tells the world that every server is permitted.

DKIM: proof the message was not altered

DKIM adds a cryptographic signature to each message you send. The matching public key sits in your DNS, so a receiver can confirm the message really came through your mail system and was not changed on the way. You switch it on in your mail provider's settings and publish the key they give you. Each service that sends for you needs its own.

DMARC: what to do when the checks fail

SPF and DKIM on their own only produce a pass or a fail. DMARC is the instruction that tells receiving servers what to do with a failure, and it asks them to send you reports. It has three settings.

  • p=none: deliver everything, but send me reports. This is monitoring only.
  • p=quarantine: put failing messages in the spam folder.
  • p=reject: refuse failing messages outright.

The safe order to turn them on

  1. List everything that sends email as your domain: your mailboxes, plus any billing, booking, marketing, or support tools.
  2. Publish one SPF record covering all of them, and turn on DKIM for each.
  3. Publish DMARC at p=none and read the reports for a few weeks. They show who is sending as you, including services you forgot.
  4. Once the legitimate senders all pass, move to p=quarantine, then to p=reject.

Skipping step three is how businesses break their own email. Going straight to p=reject with a forgotten sender means real invoices and appointment reminders vanish without anyone being told.

What these records do not do

They stop other people sending as your exact domain. They do not stop a lookalike domain with one letter changed, and they do not stop phishing sent to your staff from someone else's address. Filtering and staff awareness cover those. But a domain with no DMARC policy is an open invitation, and it is the first thing we check.

Locked down. Not locked in.

Tell us what you're dealing with. We'll work out what you need and give you a fixed-price quote. Scoping conversations are free, and we reply within 24 hours.