Email Authentication: SPF, DKIM and DMARC Explained

Table of Contents

Email is still one of the most important ways businesses communicate with customers, suppliers and staff — but it is also one of the easiest channels for attackers to abuse. Without the right protection in place, someone could send emails that appear to come from your domain, putting your reputation, customers and deliverability at risk.

SPF, DKIM and DMARC are three email authentication records that help prove your emails are genuine and reduce the chances of your domain being spoofed. They also play a major role in whether your emails reach the inbox or end up in junk. In this guide, we explain what SPF, DKIM and DMARC mean, how they work together, and why every business should make sure they are configured correctly.

What is SPF, DKIM and DMARC?

SPF explained

Sender Policy Framework (SPF) is an email authentication policy. You can register IP addresses that are authorised to send emails from your domain and should be trusted.

When emails are sent out they go through an authentication process before they reach your inbox. By adding your Mail Server IP, your deliverability will improve as emails coming from this address can be verified against your domain.

DKIM explained

A Domain Keys Identified Mail is another method of email authentication. This method adds an encrypted digital signature to your email which is used to verify that the email has indeed been sent by an owner of the domain.

Setting this up correctly helps verify the emails message and body, and that attachments have not been modified. This is also true for messages that are being forwarded.

DMARC explained

Domain-based Message Authentication, Reporting and Conformance allows you to decide how emails that do not pass SPF and DKIM checks should be treated. It also enables you to keep track of instances when someone tries to impersonate your domain.

By configuring your DMARC policy you can choose if you want unauthorised mail to go into spam, be rejected or ignored by the recipient’s inbox. 

The main benefit of this is that you are protecting your brand reputation, which can be affected by scammers spoofing recipients using your domain. This can then negatively impact your deliverability.

On top of that it allows you to monitor who is sending emails from your domain, giving you greater insight into how your domain is being used.

Why SPF, DKIM and DMARC matter

SPF, DKIM and DMARC matter because they help prove that emails sent from your domain are genuine. Without them, it can be much easier for attackers to impersonate your business by sending emails that look like they have come from your domain. This is known as email spoofing, and it is commonly used in phishing attacks, invoice fraud, fake password reset emails and other scams.

They also play an important role in email deliverability. If your email authentication records are missing, incorrect or incomplete, receiving mail servers may be less likely to trust your messages. This can result in legitimate emails being rejected, quarantined or sent to junk folders, even when they have been sent by your own team.

SPF tells receiving mail servers which systems are allowed to send email for your domain. DKIM adds a digital signature to help prove the message has not been altered. DMARC brings SPF and DKIM together by telling receiving mail servers what to do when an email fails authentication checks.

For businesses, this is especially important because email is often sent from more than one place. You may use Microsoft 365 or Google Workspace for normal email, but your website, CRM, invoicing system, email marketing platform, helpdesk or booking system may also send emails on your behalf. If these services are not included or configured correctly, you could run into delivery problems or leave gaps that attackers can exploit.

Having SPF, DKIM and DMARC properly configured helps protect your domain, improves trust with receiving mail servers and reduces the risk of your business being impersonated by cyber criminals.

How to check your SPF, DKIM and DMARC records

You can check your email security easily using NCSC free email security check.

SPF, DKIM and DMARC for Microsoft 365

If your business uses Microsoft 365 for email, SPF, DKIM and DMARC should be part of your standard email security setup. When you first add a domain to Microsoft 365, you will usually be guided through the basic DNS records needed to send and receive email, including SPF. However, DKIM and DMARC are often left for later, which can leave your domain less protected and may affect how trusted your emails appear to receiving mail servers.

This is becoming increasingly important as providers such as Google and Yahoo continue to tighten their sender requirements. If your domain does not have the correct authentication records in place, your emails may be more likely to be rejected, quarantined or sent to junk — especially if you send newsletters, customer updates, invoices, website notifications or other regular business emails.

How to set-up DKIM for Microsoft 365

  1. Navigate to https://security.microsoft.com/dkimv2 and login as a global admin user.
  2. On the Email authentication settings page, select the DKIM tab.
  3. On the DKIM tab, click on the domain you would like to configure DKIM for.
  4. Then, click create DKIM keys
  5. You will then be provided with two CNAME DNS records that need creating. Please continue to add these DNS records or ask your local IT team to add these for you.
  6. After a few hours, please return back to the Security Admin Center and enable DKIM for your domain.

Is SPF, DKIM and DMARC enough to protect your business email?

SPF, DKIM and DMARC are an important part of email security, but they are not a complete solution on their own. They help receiving mail servers check whether an email claiming to come from your domain is genuine, and they can reduce the risk of your domain being used for spoofing. However, they do not stop every type of email threat.

Attackers can still send phishing emails from lookalike domains, compromised supplier accounts, free email addresses or legitimate platforms that have been abused. A message may pass SPF, DKIM and DMARC checks and still contain a malicious link, fake invoice, dangerous attachment or convincing social engineering attempt.

This is why email authentication should be treated as one layer of protection, not the whole security strategy. Your business should also have protection against phishing, malware, ransomware, impersonation, suspicious links, malicious attachments and account compromise attempts.

For stronger protection, Globe2’s Email Threat Protection service helps defend Microsoft 365 and business email users against modern email-based attacks. It adds advanced filtering, threat detection and security controls to help stop dangerous emails before they reach your team.

If you are reviewing SPF, DKIM and DMARC because of deliverability issues, spoofing concerns or recent phishing attempts, it may also be the right time to review your wider email security setup.

Need help setting up email authentication?

If you are unsure whether your SPF, DKIM and DMARC records are correct, it is worth getting them reviewed before making major changes. Email authentication is powerful, but an incorrect record can stop legitimate emails from reaching customers, suppliers or staff.

Globe2 can help check your current email authentication setup, identify missing or misconfigured records, and make sure your domain is protected without disrupting normal email delivery. We can review your DNS, Microsoft 365 configuration, website forms, CRM, marketing platforms and any other systems that send email on behalf of your domain.

Get In Touch

Subscribe to our newsletter

Rated EXCELLENT on TrustPilot

Looking for a Managed IT Service Provider?