Imagine a family member receives an email that appears to come from your billing office, asking them to pay an invoice to a new account. Or a vendor receives a message that looks like it came from your administrator, requesting a rush payment. If criminals can send mail that appears to come from your domain, your reputation and your residents' families are at risk.
Three email authentication standards, SPF, DKIM and DMARC, help prevent this. They sound technical, but the concepts are manageable, and setting them up is usually inexpensive.
Email was designed without a strong way to prove who sent a message. Anyone can put your address in the From line. Receiving mail systems need a way to check whether a message really came from servers you authorized.
Sender Policy Framework is a record in your domain's DNS that lists which servers are allowed to send email for your domain. When a message arrives, the receiving server checks the sending server against the list.
You publish the list, which includes your email platform and any other service that sends mail on your behalf, such as a billing system, newsletter tool or survey platform
SPF has limits on complexity, so keep the list tidy
It ends with a policy describing how to treat mail from unlisted servers
DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving server uses a public key published in your DNS to verify that the message was signed by your domain and was not altered in transit.
Each sending service typically has its own key
Your email provider usually gives you the records to publish
Once enabled, signatures are added automatically
Domain-based Message Authentication, Reporting and Conformance builds on SPF and DKIM. It tells receiving servers what to do when a message fails the checks, and it sends you reports about who is sending mail using your domain.
DMARC has three policy levels:
None: Monitor only. Failing messages are still delivered, but you receive reports.
Quarantine: Failing messages are typically sent to spam
Reject: Failing messages are refused
The goal is to reach reject, which gives the strongest protection against impersonation of your domain.
Moving too fast can block your own legitimate email, so go in steps.
Inventory your senders. List every service that sends email as your domain, including those that individual departments set up.
Publish SPF and enable DKIM for your main email platform and each other legitimate sender.
Publish DMARC at none with a reporting address, and collect reports for several weeks.
Read the reports to find legitimate senders that are failing, then fix them, and spot unauthorized sources.
Move to quarantine, optionally in stages using a percentage setting, and monitor for problems.
Move to reject when you are confident that legitimate mail passes.
Keep reviewing. Add new services to your records when they are introduced.
DMARC reports are formatted for machines. Use a reporting tool or your IT provider to read them in a useful form.
Reduces the chance that criminals can impersonate your domain to families and vendors
Helps your legitimate mail reach inboxes, which matters for appointment notices and family communications
Gives you visibility into misuse of your domain
Supports your HIPAA safeguards for transmission security and workforce protection against malicious software
Some large email providers now expect bulk senders to authenticate mail, so setting this up also helps ordinary deliverability.
Publishing multiple SPF records, which is invalid. A domain should have just one.
Forgetting third-party services that send on your behalf
Setting DMARC to reject too early and blocking real mail
Never reading the reports
Ignoring look-alike domains that are not covered, such as a name with one letter changed. Consider registering obvious variants and monitoring for new ones.
These standards protect your domain, but they do not stop all phishing aimed at your staff, which can come from other domains. Keep email filtering and staff training in place.
Free lookup tools can show your current SPF, DKIM and DMARC records. If you do not have a DMARC record at all, that is the first gap to close. UnityCare IT can review your email domain settings, identify unauthorized senders and manage the staged move to enforcement.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172