Asistencia 24/7/365 · Oficina 9–17 h MT, lun–vie +1 (208) 391-7176 Team@alcousa.org

SPF, DKIM and DMARC: why your domain is probably still spoofable

Most organizations have all three records in place. A surprising number have them configured just wrong enough to do nothing.

Email was designed in an era that assumed everyone on the network was trustworthy. Nothing in the basic protocol stops someone from putting your domain in the "From" field and sending mail as you. Three standards were added over the years to fix that — SPF, DKIM and DMARC — and used together they work well. The problem we see is not that organizations lack them. It is that they have them, believe they are protected, and are not.

What the three actually do

SPF publishes a list of the servers allowed to send mail for your domain. DKIM cryptographically signs your mail so a recipient can confirm it was not altered and genuinely came from you. DMARC ties the two together and, crucially, tells receiving servers what to do when a message fails — and asks them to report back.

Where it goes wrong

The most common failure is DMARC left on "p=none." That setting turns on reporting but instructs the world to do nothing about forgeries. It is meant to be a temporary observation phase while you find your legitimate senders. Many domains have sat in p=none for years, which is the security equivalent of installing a camera and never plugging it in. The other frequent problem is an SPF record that has quietly broken. Every marketing tool, invoicing system and helpdesk that sends "on your behalf" needs to be included; add a new one, forget the record, and its mail starts failing — or you paper over it with an overly broad rule that defeats the purpose.

Why it matters beyond spam

Domain spoofing is how invoice-fraud and payroll-diversion emails earn their credibility. When a message that appears to come from your CEO or your finance team lands cleanly in an inbox, the recipient's guard is already down. Enforced DMARC does not fix human judgment, but it removes the easiest way to impersonate you outright.

What "done" looks like

Every legitimate sender accounted for in SPF and signing with DKIM; DMARC moved to "quarantine" and then "reject"; and someone actually reading the aggregate reports each month. It is a couple of afternoons of careful work, not a project — and it is worth doing before someone does it to you.

Más de ALCO

What good IT reporting should tell you

If you fund IT but can't see what it's doing, you're paying on faith. Here's what a clear report should show — and why i

Leer más

Reuse is the real password problem

The weak password is rarely the one that gets you breached. The reused one is.

Leer más

What break-fix really costs

Paying only when something breaks looks like the frugal choice. The math usually says otherwise.

Leer más

¿Encaja con lo que necesita?

Cualificamos cada proyecto antes de presupuestarlo. Eso significa una conversación técnica sobre su infraestructura, no una llamada comercial, y una respuesta clara si no somos la firma adecuada.

Veamos qué está ejecutando.

Una conversación de alcance con un ingeniero sénior. Le diremos qué cambiaríamos, cuánto costaría y si somos la firma adecuada para ello.