Cyber Readiness Pro
Back to insights

Rule explainer

SPF, DKIM and DMARC: the email authentication most businesses miss

These three settings work together to stop someone else sending email that looks like it came from your domain. SPF is a list of which mail servers are actually allowed to send email on your behalf. DKIM adds a cryptographic signature to outgoing mail, proving it wasn't altered in transit. DMARC is the policy layer on top: it tells receiving mail servers what to do when a message fails those checks (reject it, quarantine it, or let it through), and gives you visibility into who's been sending email pretending to be you.

None of this is visible in day-to-day email use, which is exactly why it gets missed. There's no login screen or setting your team sees, it's configured once in your domain's DNS records and then forgotten, often because whoever set up email hosting years ago either didn't configure it fully or configured SPF and DKIM but never tightened DMARC beyond "monitor only."

It's configured once in your domain's DNS records and then forgotten.

The reason it matters goes beyond any single certification: domain spoofing and business email compromise (someone impersonating your business, or a supplier impersonating theirs to you) are among the most common ways businesses actually get defrauded, and correctly configured SPF, DKIM and DMARC is one of the most effective, lowest-cost defences against it.

Worth knowing

Domain spoofing and business email compromise are among the most common ways businesses actually get defrauded, and correctly configured SPF, DKIM and DMARC is one of the cheapest, most effective defences against it.

It's also a specific, checkable thing rather than a vague "improve your email security" task. Run the free 5-minute readiness check to see where this and other commonly missed gaps sit for your business.