Email security

DMARC, SPF and DKIM: stop attackers spoofing your domain

Phish Plug ResearchMay 20, 20269 min read

If attackers can send email as your domain, every other defence is working uphill. Three standards decide whether they can: SPF, DKIM and DMARC. Together they are the foundation of email authentication — and the single most effective step against spoofing and many forms of phishing.

SPF: who is allowed to send

SPF (Sender Policy Framework) is a published list of the servers permitted to send mail for your domain. A receiving server checks whether the message came from one of them. If not, that is a signal the mail may be forged.

DKIM: proof it really came from you

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your messages. The receiver verifies it against a public key you publish, confirming the message genuinely came from your domain and was not altered in transit.

DMARC: enforcement and visibility

DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together. It tells receiving servers what to do when a message fails — do nothing, quarantine it, or reject it — and it sends you reports on who is sending mail as your domain, legitimate or not.

SPF and DKIM are the checks; DMARC is the decision and the dashboard. Without a DMARC policy of quarantine or reject, a failing message can still land in the inbox.

Rolling it out without breaking mail

  1. Configure SPF and DKIM correctly for every service that sends as you.
  2. Publish DMARC at p=none and collect reports — monitor only, block nothing.
  3. Review the reports to find all legitimate senders and fix any gaps.
  4. Tighten to quarantine, then reject once you are confident legitimate mail passes.

Jumping straight to reject is the classic mistake — it can block your own newsletters, tools and third-party senders. Stage it.

Email authentication stops attackers using your exact domain. They then fall back on lookalike domains — which Phish Plug is built to detect and take down.

The takeaway

SPF says who may send, DKIM proves it was really you, and DMARC enforces and reports. Rolled out in stages to reject, they make your exact domain very hard to spoof — closing the door that BEC and much phishing rely on, and pushing attackers onto lookalikes you can then hunt.

See your brand's exposure in one pass

Run a free clone check on one domain — lookalikes surfaced, cloaking proven, evidence captured.