SPF, DKIM and DMARC: why your domain is probably still spoofable
Most organizations have all three records in place. A surprising number have them configured just wrong enough to do nothing.
Email was designed in an era that assumed everyone on the network was trustworthy. Nothing in the basic protocol stops someone from putting your domain in the "From" field and sending mail as you. Three standards were added over the years to fix that — SPF, DKIM and DMARC — and used together they work well. The problem we see is not that organizations lack them. It is that they have them, believe they are protected, and are not.
What the three actually do
SPF publishes a list of the servers allowed to send mail for your domain. DKIM cryptographically signs your mail so a recipient can confirm it was not altered and genuinely came from you. DMARC ties the two together and, crucially, tells receiving servers what to do when a message fails — and asks them to report back.
Where it goes wrong
The most common failure is DMARC left on "p=none." That setting turns on reporting but instructs the world to do nothing about forgeries. It is meant to be a temporary observation phase while you find your legitimate senders. Many domains have sat in p=none for years, which is the security equivalent of installing a camera and never plugging it in. The other frequent problem is an SPF record that has quietly broken. Every marketing tool, invoicing system and helpdesk that sends "on your behalf" needs to be included; add a new one, forget the record, and its mail starts failing — or you paper over it with an overly broad rule that defeats the purpose.
Why it matters beyond spam
Domain spoofing is how invoice-fraud and payroll-diversion emails earn their credibility. When a message that appears to come from your CEO or your finance team lands cleanly in an inbox, the recipient's guard is already down. Enforced DMARC does not fix human judgment, but it removes the easiest way to impersonate you outright.
What "done" looks like
Every legitimate sender accounted for in SPF and signing with DKIM; DMARC moved to "quarantine" and then "reject"; and someone actually reading the aggregate reports each month. It is a couple of afternoons of careful work, not a project — and it is worth doing before someone does it to you.
المزيد من ALCO
What good IT reporting should tell you
If you fund IT but can't see what it's doing, you're paying on faith. Here's what a clear report should show — and why i
اقرأ المزيدReuse is the real password problem
The weak password is rarely the one that gets you breached. The reused one is.
اقرأ المزيدWhat break-fix really costs
Paying only when something breaks looks like the frugal choice. The math usually says otherwise.
اقرأ المزيدهل هذا مناسب لك؟
نُقيّم ملاءمة كل مشروع قبل تسعيره. أي محادثة تقنية عن بنيتك التحتية، لا مكالمة مبيعات — وإجابة صريحة إن لم نكن الشركة المناسبة.