Email Authentication to Stop Spoofing of Your Administrators Name

Imagine a family member receiving an email that appears to come from your administrator, asking them to update payment information. The name and address look right, but the message was sent by a criminal. Without proper email authentication, it is surprisingly easy to forge the sender address of an organization's domain.

Three technical settings, SPF, DKIM and DMARC, help receiving mail systems decide whether a message really came from you. They live in your domain's DNS records, and setting them up is a task for your IT provider. Administrators do not need to configure them but should understand why they matter and ask whether they are in place.

SPF: who is allowed to send

Sender Policy Framework is a published list of the servers and services permitted to send email on behalf of your domain. When a message arrives claiming to be from your organization, the receiving system checks whether it came from an approved sender.

Your list should include your email provider and any other services that send on your behalf, such as a newsletter platform, a billing system, an online forms tool or a fax-to-email service. If you forget one, legitimate messages may be rejected.

DKIM: a digital signature

DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving system uses a public key published in your DNS to verify that the message was really sent by an authorized system and was not altered in transit.

DKIM must be enabled for each service that sends mail for you. Your email provider has instructions for turning it on.

DMARC: what to do when checks fail

Domain-based Message Authentication, Reporting and Conformance builds on SPF and DKIM. It tells receiving systems what to do with messages that fail authentication, and it sends you reports about who is sending mail using your domain.

A DMARC policy has three levels:

None: monitor only. Failed messages are still delivered, but you receive reports.

Quarantine: failed messages are usually sent to spam.

Reject: failed messages are blocked.

Why it matters for care organizations

Protects families and partners from fraudulent messages that appear to come from you.

Protects your reputation. Criminals using your domain can damage trust and cause your genuine mail to be flagged as spam.

Improves delivery. Major mailbox providers expect authenticated mail, and unauthenticated messages are more likely to be filtered.

Supports security questionnaires. Insurers and partners increasingly ask whether these protections are in place.

They do not stop phishing messages from other domains aimed at your staff, so they work alongside email filtering and training.

How to roll it out safely

Inventory senders. List every system that sends email using your domain.

Publish SPF including all legitimate senders.

Enable DKIM for each sender.

Publish DMARC in monitoring mode and set an address to receive reports.

Review reports for a few weeks. Look for legitimate services that fail checks and fix them, and note unauthorized senders.

Move to quarantine and then reject when you are confident that legitimate mail passes.

Moving too fast to a strict policy can block real mail, such as invoices or resident communications. Moving too slowly leaves the door open. A staged approach with monitoring balances the two.

Common pitfalls

Forgetting a third-party sender, like a billing service.

Having more than one SPF record, which breaks the check.

Exceeding SPF lookup limits as services pile up.

Setting DMARC to monitoring forever and never enforcing.

Not reviewing reports, so no one notices spoofing attempts.

Overlooking other domains you own but do not use for email. These can be protected with a policy that says no mail should ever come from them.

Questions to ask your IT provider

Are SPF, DKIM and DMARC in place for all of our domains?

What is our DMARC policy today, and what is the plan to enforce it?

Who reviews the reports, and how often?

Which services send mail on our behalf?

How UnityCare IT can help

UnityCare IT configures and monitors email authentication for healthcare and senior living organizations. If you are not sure what your domain's records say today, we can check them and walk you through the results.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034