DMARC, SPF and DKIM: stop attackers spoofing your domain
If attackers can send email as your domain, every other defence is working uphill. Three standards decide whether they can: SPF, DKIM and DMARC. Together they are the foundation of email authentication — and the single most effective step against spoofing and many forms of phishing.
SPF: who is allowed to send
SPF (Sender Policy Framework) is a published list of the servers permitted to send mail for your domain. A receiving server checks whether the message came from one of them. If not, that is a signal the mail may be forged.
DKIM: proof it really came from you
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your messages. The receiver verifies it against a public key you publish, confirming the message genuinely came from your domain and was not altered in transit.
DMARC: enforcement and visibility
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together. It tells receiving servers what to do when a message fails — do nothing, quarantine it, or reject it — and it sends you reports on who is sending mail as your domain, legitimate or not.
SPF and DKIM are the checks; DMARC is the decision and the dashboard. Without a DMARC policy of quarantine or reject, a failing message can still land in the inbox.
Rolling it out without breaking mail
- Configure SPF and DKIM correctly for every service that sends as you.
- Publish DMARC at p=none and collect reports — monitor only, block nothing.
- Review the reports to find all legitimate senders and fix any gaps.
- Tighten to quarantine, then reject once you are confident legitimate mail passes.
Jumping straight to reject is the classic mistake — it can block your own newsletters, tools and third-party senders. Stage it.
Email authentication stops attackers using your exact domain. They then fall back on lookalike domains — which Phish Plug is built to detect and take down.
The takeaway
SPF says who may send, DKIM proves it was really you, and DMARC enforces and reports. Rolled out in stages to reject, they make your exact domain very hard to spoof — closing the door that BEC and much phishing rely on, and pushing attackers onto lookalikes you can then hunt.
Keep reading
Related articles
Email spoofing: how attackers fake your 'from' address
Why email lets anyone forge a sender, how spoofing underpins phishing and BEC, and the authentication that makes your domain hard to impersonate.
Read article Detection · 8 minDomain monitoring: a practical buyer's guide
What domain monitoring should actually do, the signals that matter, and the questions to ask — so you catch lookalikes early instead of paying for noise.
Read article Best practices · 7 minBrandjacking: when someone hijacks your identity online
Brandjacking covers domains, social handles, ads and apps that seize your identity. The forms it takes and how to reclaim and defend your brand.
Read articleSee your brand's exposure in one pass
Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.