Imagine a family member receives an email that appears to come from your administrator, asking them to update billing information. Or a vendor receives a message from your accounts payable address with new payment instructions. Neither message came from your systems, but without the right email authentication settings, the recipient's mail service has no reliable way to know that.
Three standards address this problem: SPF, DKIM and DMARC. They sound technical, but the ideas are simple, and setting them up is one of the most cost-effective email protections available. They also protect your reputation, so legitimate messages from your organization are not sent to spam.
The original email system trusted whatever sender address a message claimed. That makes impersonation easy. SPF, DKIM and DMARC let a domain owner publish rules, in public DNS records, about who may send email for the domain and what receivers should do with messages that fail the checks.
Sender Policy Framework is a DNS record listing the mail servers and services authorized to send email on behalf of your domain. Typically this includes your email platform, such as Microsoft 365 or Google Workspace, plus any other service that sends messages as you, such as a newsletter tool, a billing system or a website contact form.
When a receiving server gets a message claiming to be from your domain, it checks whether the sending server is on the list. If not, SPF fails.
Keep in mind that SPF has limits, including a cap on the number of lookups a record can trigger, so records need maintenance as services are added.
DomainKeys Identified Mail adds a digital signature to outgoing messages. Your sending service signs each message using a private key, and you publish the matching public key in DNS. The receiving server uses it to verify that the message really came from an authorized source and that the content was not changed in transit.
Each service that sends mail for you generally needs its own DKIM setup.
Domain-based Message Authentication, Reporting and Conformance ties the other two together. A DMARC record tells receivers what to do when a message fails authentication and aligns poorly with the visible From address, and where to send reports.
There are three policy levels.
None: monitor only. Receivers deliver messages but send you reports.
Quarantine: suspicious messages are sent to spam.
Reject: failing messages are refused.
The reports show who is sending email using your domain, including legitimate services you forgot about and impersonators.
Moving straight to a strict policy can block your own legitimate email, such as invoices sent by a billing system. Take it in steps.
Inventory your senders. List every system that sends email using your domain, including those managed by other departments or vendors.
Publish SPF that includes all legitimate senders.
Enable DKIM for your main email platform and for third-party services.
Publish DMARC at the monitoring level, with a mailbox or reporting service that collects the reports.
Review the reports for several weeks. Fix legitimate senders that fail, and note unauthorized sources.
Move to quarantine, then to reject, once the legitimate mail passes consistently. Many organizations raise enforcement gradually.
Large mailbox providers have tightened expectations for bulk senders in recent years, and authentication is a core part of that. If you send newsletters or notices in volume, check current sender requirements.
Look-alike domains, such as a name with one character changed, are not blocked by your DMARC record. Consider registering obvious variants, and monitor for new look-alikes.
Your inbound protections matter too. Email filtering, link scanning and attachment controls help block messages sent to your staff.
Authentication supports, but does not replace, staff awareness. A message from a hacked legitimate account will pass these checks.
Email is a common channel for phishing, business email compromise and unauthorized disclosure. Strong authentication reduces the chance that an attacker can impersonate your organization to residents' families, vendors and staff. It supports the security awareness and technical safeguards that the HIPAA Security Rule expects, and it is the kind of control cyber insurers ask about.
Free public tools let you look up your domain's SPF, DKIM and DMARC records. If you see no DMARC record, or a policy of none that has been in place for years, there is room to improve. Your domain registrar or DNS host controls where these records are edited, so make sure you know who has access to that account and protect it with multi-factor authentication.
UnityCare IT helps healthcare organizations inventory their email senders, publish the right records and move carefully toward enforcement, so legitimate mail keeps flowing while impersonators are stopped.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172