Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

Email Spoofing

How SPF, DKIM and DMARC protect your business from email spoofing

Without the right security measures, criminals can send emails that appear to come from your business. They can use your domain, copy your branding and trick customers or suppliers into paying fake invoices or changing bank details. This is known as email spoofing and is one of the most common starting points for business email fraud.

Three DNS records help prevent this:

  • SPF - identifies which mail servers are authorised to send email for your domain.
  • DKIM - digitally signs outgoing emails, proving they came from your domain and haven't been altered.
  • DMARC - brings SPF and DKIM together, telling receiving mail servers what to do with messages that fail authentication while providing reports on who is sending email using your domain.

Many businesses have SPF and DKIM configured but never fully implement DMARC, leaving their domain vulnerable.

Why Email Spoofing Happens

Email was never designed with modern security threats in mind.

By default, receiving mail servers don't automatically verify that the sender really owns the domain shown in the From address. Without SPF, DKIM and DMARC, a scammer can send an email that appears to come from your business, making it much easier to deceive customers, suppliers and employees.

Understanding SPF, DKIM and DMARC

SPF (Sender Policy Framework)

SPF publishes a list of the mail servers authorised to send email on behalf of your domain. Messages sent from unauthorised servers are flagged as suspicious.

DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic signature to every outgoing email. Receiving mail servers use this to verify that the message genuinely came from your domain and hasn't been modified in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC enforces your email authentication policy. It checks that SPF and DKIM align with the visible sender address, tells receiving servers how to handle failed messages and provides reports showing who is sending email using your domain.

The DMARC mistake many businesses make

The right setup depends on your team, your tools, and how your accounts are currently structured.

DMARC has three policy levels:

  • p=none – Monitor only. Emails that fail authentication are still delivered.
  • p=quarantine – Suspicious emails are sent to the recipient's junk folder.
  • p=reject – Failed emails are blocked completely.

Many organisations stop at p=none, which provides reporting but doesn't prevent spoofing. Once you've confirmed legitimate email is passing authentication, moving to p=reject offers the strongest protection.

What these records don't prevent

SPF, DKIM and DMARC protect your domain, but they don't stop every type of impersonation.

They won't prevent:

  • Lookalike domains, such as yourcompany-support.co.uk
  • Display name spoofing, where the sender name appears legitimate but the underlying email address is different

Staff should always check the full sender address and verify any request to change payment details using a trusted telephone number.

Why every business should use them

Email authentication isn't just about security—it also improves email delivery. Major providers including Google, Yahoo and Microsoft increasingly expect domains to use SPF, DKIM and DMARC. Properly authenticated email is far more likely to reach recipients' inboxes instead of their spam folder.

Checking Your Domain

Free online SPF, DKIM and DMARC lookup tools can quickly show whether your domain has these records in place.

A phased approach helps protect your domain without disrupting genuine email. If changes are needed, they should be implemented carefully:

  1. Configure SPF and DKIM for all legitimate email services.
  2. Enable DMARC with p=none and review the reports.
  3. Progress to p=quarantine, then p=reject once legitimate email is consistently passing.
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?