Helpdesk 24/7/365 · Büro 9–17 Uhr MT, Mo–Fr +1 (208) 391-7176 Team@alcousa.org

SPF, DKIM and DMARC: why your domain is probably still spoofable

Most organizations have all three records in place. A surprising number have them configured just wrong enough to do nothing.

Email was designed in an era that assumed everyone on the network was trustworthy. Nothing in the basic protocol stops someone from putting your domain in the "From" field and sending mail as you. Three standards were added over the years to fix that — SPF, DKIM and DMARC — and used together they work well. The problem we see is not that organizations lack them. It is that they have them, believe they are protected, and are not.

What the three actually do

SPF publishes a list of the servers allowed to send mail for your domain. DKIM cryptographically signs your mail so a recipient can confirm it was not altered and genuinely came from you. DMARC ties the two together and, crucially, tells receiving servers what to do when a message fails — and asks them to report back.

Where it goes wrong

The most common failure is DMARC left on "p=none." That setting turns on reporting but instructs the world to do nothing about forgeries. It is meant to be a temporary observation phase while you find your legitimate senders. Many domains have sat in p=none for years, which is the security equivalent of installing a camera and never plugging it in. The other frequent problem is an SPF record that has quietly broken. Every marketing tool, invoicing system and helpdesk that sends "on your behalf" needs to be included; add a new one, forget the record, and its mail starts failing — or you paper over it with an overly broad rule that defeats the purpose.

Why it matters beyond spam

Domain spoofing is how invoice-fraud and payroll-diversion emails earn their credibility. When a message that appears to come from your CEO or your finance team lands cleanly in an inbox, the recipient's guard is already down. Enforced DMARC does not fix human judgment, but it removes the easiest way to impersonate you outright.

What "done" looks like

Every legitimate sender accounted for in SPF and signing with DKIM; DMARC moved to "quarantine" and then "reject"; and someone actually reading the aggregate reports each month. It is a couple of afternoons of careful work, not a project — and it is worth doing before someone does it to you.

Mehr von ALCO

What good IT reporting should tell you

If you fund IT but can't see what it's doing, you're paying on faith. Here's what a clear report should show — and why i

Weiterlesen

Reuse is the real password problem

The weak password is rarely the one that gets you breached. The reused one is.

Weiterlesen

What break-fix really costs

Paying only when something breaks looks like the frugal choice. The math usually says otherwise.

Weiterlesen

Passt das zu Ihnen?

Wir qualifizieren jedes Mandat, bevor wir es anbieten. Das heißt: ein technisches Gespräch über Ihre Systemlandschaft, kein Verkaufsgespräch — und eine klare Antwort, wenn wir nicht die richtige Firma sind.

Sehen wir uns an, was Sie betreiben.

Ein Scoping-Gespräch mit einem erfahrenen Ingenieur. Wir sagen Ihnen, was wir ändern würden, was es kosten würde, und ob wir dafür die richtige Firma sind.