Email Authentication: Stop Attackers from Sending Email That Looks Like It Came from You
Right now, anyone can send an email that looks like it came from your domain. SPF, DKIM, and DMARC are three free DNS records that stop this. Set them up in 30 minutes β no technical skills required.
The Problem: Your Domain Is Being Impersonated Right Now
Email was designed in the 1970s, when everyone on the internet knew each other. There is no built-in way to verify that an email claiming to be from @yourcompany.com actually came from your company. Attackers exploit this every day β sending fake invoices from "your" domain to your customers, phishing emails to your employees that appear to come from HR, and vendor payment requests that look like they came from your CEO.
The fix is three DNS records that together tell the world: "If an email claims to be from our domain but did not come from our approved mail servers, it is fake. Reject it." These records are free to set up and take about 30 minutes for most small businesses.
The Three Protocols Explained (in Plain English)
π SPF (Sender Policy Framework)
SPF is a list of servers authorized to send email from your domain. It is like a bouncer at a club with a guest list. If a server not on the list tries to send email as @yourcompany.com, receiving mail servers know it is unauthorized.
Example: "v=spf1 include:_spf.google.com ~all" means "Only Google's mail servers can send email for this domain. Treat anything else as suspicious."
π DKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to every email you send. The receiving server checks this signature against a public key published in your DNS. If the signature is valid, the email has not been tampered with in transit. Think of it as a tamper-evident seal on a package.
π‘οΈ DMARC (Domain-based Message Authentication, Reporting & Conformance)
DMARC is the policy layer on top of SPF and DKIM. It tells receiving servers: "Here is what to do with emails that fail SPF or DKIM checks β quarantine them, reject them, or let them through." It also sends you reports showing who is trying to spoof your domain (and how often β you will be surprised).
Step-by-Step: Set Up All Three in 30 Minutes
Step 1: Set up SPF
Log into your domain registrar's DNS management (GoDaddy, Namecheap, Cloudflare, etc.). Create a TXT record for your root domain (@) with the appropriate value for your email provider:
- Google Workspace:
v=spf1 include:_spf.google.com ~all - Microsoft 365:
v=spf1 include:spf.protection.outlook.com ~all - Both + other services: Combine them:
v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all
The ~all at the end means "soft fail" β suspicious but not rejected. Once you are confident your SPF record is correct, you can change this to -all (hard fail β reject anything not on the list).
Step 2: Enable DKIM
DKIM is enabled in your email admin console, not your DNS:
- Google Workspace: Admin β Apps β Google Workspace β Gmail β Authenticate email β Generate DKIM key. Copy the provided DNS record and add it to your domain's DNS.
- Microsoft 365: DKIM is enabled automatically for custom domains. Verify in Security Admin β Email & collaboration β DKIM.
Step 3: Publish a DMARC policy
Create a TXT record at _dmarc.yourdomain.com with a policy. Start with monitoring mode first:
v=DMARC1; p=none; rua=mailto:you@yourcompany.com; ruf=mailto:you@yourcompany.com
This tells receiving servers: "Start checking SPF/DKIM, do not reject anything yet, and send me reports." After a few weeks of reviewing reports, tighten it:
v=DMARC1; p=quarantine; pct=100; rua=mailto:you@yourcompany.com
Eventually, move to p=reject β this is the gold standard. It tells the world: "If email from my domain fails SPF or DKIM, do not deliver it at all."
β οΈ Common Mistakes to Avoid
- β’ Forgetting third-party senders: If you use Mailchimp, HubSpot, or any service that sends email "from" your domain, you must include them in your SPF record. Most services provide their SPF include value in their documentation.
- β’ Jumping straight to p=reject: Start with p=none. Monitor for a few weeks. Make sure legitimate email is not being flagged. Then escalate.
- β’ Only setting SPF without DKIM: SPF alone is not enough. DKIM adds the signature that DMARC checks. You need both for full protection.
- β’ Not monitoring DMARC reports: The reports tell you who is spoofing your domain. They are worth reading β many businesses discover spoofing campaigns they had no idea about.
Free Tools to Check Your Setup
- MXToolbox SPF Checker β instant validation
- MXToolbox DKIM Checker
- Dmarcian DMARC Inspector β validate and test your DMARC record
- Google Admin Toolbox β Check MX for Google Workspace users
The Bottom Line
SPF, DKIM, and DMARC are not optional anymore. Google and Yahoo started requiring DMARC for bulk senders in 2024. Without these records, your email is more likely to land in spam folders, and your domain is trivial for attackers to impersonate. The three records take about 30 minutes to set up, cost nothing, and protect both your business and your customers from one of the most common and effective attack techniques.