SPF, DKIM and DMARC: Email Authentication Explained Simply

Anyone can send mail pretending to be your company unless you stop them. Here is what SPF, DKIM and DMARC actually do, in plain language.
MacBook laptop on a black surface, the everyday device where email authentication protects business mail

Your domain name carries your reputation. When a customer receives a message from your company, they assume it really came from you. Criminals know that, and email spoofing of an unprotected domain takes them about five minutes.

Email authentication is what stops it. Three DNS records, SPF, DKIM and DMARC, tell every mail server in the world which systems are allowed to send on your behalf and what should happen to everything else. Set them up properly and fake invoices in your name stop landing in customer inboxes. Set them up badly and your own newsletter ends up in spam.

MacBook laptop on a black surface, the everyday device where email authentication protects business mail

Why email authentication matters more than ever

Business email compromise is one of the most expensive attacks around, and it rarely involves clever hacking. Someone sends a convincing message from something that looks like your finance address, and a payment goes to the wrong bank account.

Since 2024, Google and Microsoft both require bulk senders to authenticate their mail. Providers are steadily tightening the rules. Domains without proper email authentication get filtered harder, and that hits your delivery rate before it ever hits your business email security.

There is a second benefit that surprises people. Once you can see who is sending mail using your domain, you usually discover three or four forgotten systems doing it: an old CRM, a webshop plugin, a mail platform someone signed up for years ago.

SPF: who is allowed to send for you

SPF, short for Sender Policy Framework, is a public list of the servers permitted to send mail for your domain. A receiving server checks the sending address against that list. No match, and the message looks suspicious.

The catch is the lookup limit. SPF allows a maximum of ten DNS lookups, and every service you add eats into it. Microsoft 365, your marketing platform, your invoicing tool and your support desk together will quietly break the record. Once you exceed the limit, SPF fails entirely, and most people never notice.

DKIM: proof that nothing was changed

DKIM adds a cryptographic signature to every message you send. The receiving server looks up your public key in DNS and checks the signature. If the content was altered on the way, the check fails.

Where SPF says “this server may send”, DKIM says “this message is genuine and unmodified”. You want both, because forwarding breaks SPF but usually leaves DKIM intact. That is exactly why the third record exists.

DMARC: the policy that ties it together

Your DMARC policy is the instruction manual. It tells receiving servers what to do when email authentication fails, and it asks them to send you reports about it.

  • p=none changes nothing and only collects data. This is where you start.
  • p=quarantine sends failing mail to the spam folder.
  • p=reject blocks it outright. This is the finish line.

Most companies get stuck at the first step. The record goes live, reports start arriving as dense XML files, nobody reads them, and the domain sits on p=none for two years. Technically that counts as email authentication. Practically it protects nobody, because you never told anyone to block the fakes.

Where email authentication usually goes wrong

We see the same handful of problems again and again:

  • Two SPF records on one domain, which invalidates both
  • The ten lookup limit quietly exceeded after adding a new tool
  • DKIM enabled in Microsoft 365 but never actually switched on for the custom domain
  • A DMARC policy set to reject too quickly, killing legitimate invoices from a billing platform
  • Parked domains left wide open, which are the easiest ones to spoof

That last one matters. Every domain you own needs email authentication, including the ones that never send anything. An unused domain with no records is a free tool for an attacker, and email spoofing from a forgotten domain still lands in your customer’s inbox with your name on it.

Getting it right without the guesswork

The safe route is boring and sequential. Inventory every system that sends mail for you. Publish one clean SPF record. Enable DKIM everywhere, including your marketing tools. Start your DMARC policy on p=none, read the reports for a few weeks, fix what breaks, then move to quarantine and finally to reject.

Done properly, this takes a few hours spread over a month or two, plus someone who can read the reports and knows which failures are real. Done in a hurry on a Friday afternoon, it takes down your order confirmations.

Let us handle your email authentication

This is exactly the kind of job that looks small and turns into an afternoon of DNS trial and error. You have a business to run, and email authentication is not where your time should go.

At EvolvingDesk we do this for our clients as part of managed IT. We map every sending system, publish the records, monitor the DMARC reports and walk your domain up to a reject policy without breaking a single legitimate message. After that we keep watching, because every new tool you adopt affects the setup.

You get a domain nobody can spoof, better inbox delivery, and no DNS puzzles on your desk. That is what Making IT Effortless means in practice, and it is the least glamorous and most valuable part of business email security.

Want your email authentication checked? Plan a call with us and we will tell you exactly where your domain stands, no obligation.

Read more

Useful external references: the official DMARC overview and the Microsoft documentation on email authentication.

Did this article spark some ideas?

Find out what we can do for you, schedule a call today.

About EvolvingDesk: Making IT Effortless

We turn complex IT into simple, effective solutions for your business. Whether it’s cloud services, custom applications, or network management, EvolvingDesk combines the latest technology with personal service, so your business stays secure, connected, and ready for growth. IT made simple, just the way it should be.

What do we do?

At EvolvingDesk, we provide practical IT solutions that fit the way your business works. From tailored software and reliable business WiFi to smart surveillance and hands-on support, we make sure your technology runs smoothly, so you can stay focused on your goals.

Contact-Microsoft

Development

Hosting & Cloud

Surveillance Systems

Network & WiFi

IT-Support

VoIP & Phone

E-Mail & Workspace

Point of Sale