Without the right security measures, criminals can send emails that appear to come from your business. They can use your domain, copy your branding and trick customers or suppliers into paying fake invoices or changing bank details. This is known as email spoofing and is one of the most common starting points for business email fraud.
Many businesses have SPF and DKIM configured but never fully implement DMARC, leaving their domain vulnerable.
By default, receiving mail servers don't automatically verify that the sender really owns the domain shown in the From address. Without SPF, DKIM and DMARC, a scammer can send an email that appears to come from your business, making it much easier to deceive customers, suppliers and employees.
SPF publishes a list of the mail servers authorised to send email on behalf of your domain. Messages sent from unauthorised servers are flagged as suspicious.
DKIM adds a cryptographic signature to every outgoing email. Receiving mail servers use this to verify that the message genuinely came from your domain and hasn't been modified in transit.
DMARC enforces your email authentication policy. It checks that SPF and DKIM align with the visible sender address, tells receiving servers how to handle failed messages and provides reports showing who is sending email using your domain.
DMARC has three policy levels:
Many organisations stop at p=none, which provides reporting but doesn't prevent spoofing. Once you've confirmed legitimate email is passing authentication, moving to p=reject offers the strongest protection.
They won't prevent:
Staff should always check the full sender address and verify any request to change payment details using a trusted telephone number.
Email authentication isn't just about security—it also improves email delivery. Major providers including Google, Yahoo and Microsoft increasingly expect domains to use SPF, DKIM and DMARC. Properly authenticated email is far more likely to reach recipients' inboxes instead of their spam folder.
A phased approach helps protect your domain without disrupting genuine email. If changes are needed, they should be implemented carefully:

























