SPF, DKIM and DMARC: Email Spoofing Questions Answered

Imagine a family member receiving an invoice that looks like it came from your business office, or a vendor receiving a payment change request that appears to come from your administrator. If attackers can send email that looks like it comes from your domain, they can damage trust with residents, families, referral partners and vendors.

Three email standards help prevent this: SPF, DKIM and DMARC. They sound technical, but the ideas are simple. Here are the questions we hear most often.

What is email spoofing?

Email was designed without a way to verify the sender. Anyone can type any address in the from line. Spoofing is when an attacker forges your domain, such as name@yourfacility.com, to make a message look legitimate. It is a common tool in phishing and business email compromise.

What is SPF?

Sender Policy Framework is a public list, published in your domain's DNS records, of the servers allowed to send email for your domain. When a receiving mail server gets a message that claims to be from you, it checks the list. If the message came from a server not on the list, it can be flagged or rejected.

Common pitfalls:

Forgetting a legitimate sender, such as your marketing platform, billing system or the EHR's notification service, which then fails checks.

Having more than one SPF record, which invalidates both.

Exceeding the limit of DNS lookups that SPF allows.

What is DKIM?

DomainKeys Identified Mail adds a digital signature to outgoing messages. The signature is created with a private key held by your email provider and verified using a public key published in DNS. It proves the message was authorized by your domain and was not altered in transit.

Each service that sends mail for you, whether Microsoft 365, Google Workspace or a third-party system, usually needs its own DKIM setup.

What is DMARC?

Domain-based Message Authentication, Reporting and Conformance ties the two together. A DMARC record tells receiving servers what to do when a message fails SPF and DKIM checks that align with the visible from address, and sends you reports about who is sending mail using your domain.

There are three policies:

none: monitor only. Failing messages are delivered, but you receive reports.

quarantine: failing messages are treated as suspicious, often sent to spam.

reject: failing messages are refused.

Where should we start?

Inventory every service that sends email as your domain. Ask finance, marketing, HR and clinical departments.

Publish SPF and enable DKIM for each legitimate sender.

Publish a DMARC record with the none policy and an address for reports.

Review the reports for a few weeks. They reveal forgotten senders and active abuse.

Fix legitimate failures, then move to quarantine, then to reject once you are confident.

Moving straight to reject without monitoring is a common mistake. It can block legitimate mail such as billing statements or referral notices.

Does this protect our own staff from phishing?

Indirectly. SPF, DKIM and DMARC mainly protect others from messages that falsely use your domain. On the receiving side, your email filter uses the same checks to evaluate incoming messages that claim to come from other organizations. Both directions help.

Does it stop all spoofing?

No. Attackers can still register lookalike domains, such as one that swaps a letter, and send from those. DMARC does not address those, so staff training and filtering with domain impersonation protection remain important.

Do we have to do this?

HIPAA does not specifically name these standards, but protecting the integrity of communications and guarding against malicious messages is part of a reasonable security program. Large mailbox providers now expect bulk senders to authenticate, and cyber insurers often ask whether you use DMARC. A simple policy of none is a start, but enforcement is where the protection comes from.

How do we check what we have?

Free DNS lookup and DMARC checking tools can display your current records. Look for an SPF record that ends with a clear policy, DKIM records for your providers and a DMARC record that is not simply missing.

Ongoing care

Review DMARC reports monthly at first, then quarterly.

Update records when you change email or marketing providers.

Include DNS records in your documentation so they are not lost when staff change.

How UnityCare IT helps

UnityCare IT sets up and monitors SPF, DKIM and DMARC for healthcare organizations and walks through the staged move to enforcement. If you would like us to check your current records, it takes only a few minutes.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034