Practical technology guide

SPF, DKIM and DMARC: Email Authentication in Plain English

SPF, DKIM and DMARC are three of the most useful and least understood parts of business email. They are the records that prove your messages are really from you. Set up properly they keep your email out of the spam folder and make it far harder for anyone to impersonate your domain. Left unset, they are the usual reason a smart new email setup quietly fails.

By Symnetrix / / Approximately 5 minute read

Why email needs proving at all

Email was designed to be trusting, which means anyone can claim to send from any address unless something stops them. That is how scammers spoof a business name and why legitimate mail sometimes gets treated with suspicion. SPF, DKIM and DMARC are the three checks that let a receiving server confirm a message genuinely came from your domain.

SPF: who is allowed to send

SPF is a record listing the servers permitted to send email for your domain. When a message arrives, the receiver checks whether it came from one of those approved sources. If a message claims to be from you but comes from somewhere not on the list, that is a strong sign it is not genuine, and the receiver can treat it accordingly.

DKIM: a tamper-proof signature

DKIM adds an invisible cryptographic signature to each message, which the receiving server checks against a key published on your domain. If the signature matches, the message is genuinely from you and has not been altered in transit. It is the difference between a letter that could be from anyone and one with a seal that cannot easily be faked.

Keep the goal practical. The best technology choice is the one that fits the building, workload and level of support available.

DMARC: the policy that ties it together

DMARC builds on the other two. It tells receiving servers what to do when a message fails the SPF and DKIM checks, whether to let it through, send it to spam or reject it outright, and it can report back on who is sending mail using your name. It turns the two checks into an enforceable policy rather than just information.

What happens without them

Skip these records and two things follow. Your legitimate email is more likely to be filtered as spam, because receivers cannot confirm it is really you, and your domain is easier for scammers to spoof in messages to your customers. Both undermine the trust a business email setup is supposed to build, often without anyone realising why.

Getting them right

These records reward being set up carefully and in the right order, then checked rather than assumed. A common mistake is a half-finished SPF record or a DMARC policy left in a reporting-only mode forever. Done properly, the three work quietly in the background and you simply notice that your email arrives and your name is harder to abuse.

What to do next

Have your domain checked to see whether SPF, DKIM and DMARC are present and correctly configured. If any are missing or half-set, that is very often the reason business email is landing in spam or being spoofed.

Symnetrix can check and configure SPF, DKIM and DMARC for your domain so your email reaches the inbox and your business name is harder to impersonate. Learn more about business email & microsoft 365 in Hastings and East Sussex, or contact Symnetrix to discuss your setup.

Start a conversation

Talk about business email & microsoft 365

Get practical guidance based on your premises, equipment and priorities.

Contact Symnetrix