SPF, DKIM and DMARC Explained for Healthcare Email

Imagine a family member receives an email that appears to come from your billing office, asking them to pay an invoice to a new account. Or a vendor receives a message that looks like it came from your administrator, requesting a rush payment. If criminals can send mail that appears to come from your domain, your reputation and your residents' families are at risk.

Three email authentication standards, SPF, DKIM and DMARC, help prevent this. They sound technical, but the concepts are manageable, and setting them up is usually inexpensive.

The problem they solve

Email was designed without a strong way to prove who sent a message. Anyone can put your address in the From line. Receiving mail systems need a way to check whether a message really came from servers you authorized.

SPF: the list of approved senders

Sender Policy Framework is a record in your domain's DNS that lists which servers are allowed to send email for your domain. When a message arrives, the receiving server checks the sending server against the list.

You publish the list, which includes your email platform and any other service that sends mail on your behalf, such as a billing system, newsletter tool or survey platform

SPF has limits on complexity, so keep the list tidy

It ends with a policy describing how to treat mail from unlisted servers

DKIM: a digital signature

DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving server uses a public key published in your DNS to verify that the message was signed by your domain and was not altered in transit.

Each sending service typically has its own key

Your email provider usually gives you the records to publish

Once enabled, signatures are added automatically

DMARC: the policy and the reporting

Domain-based Message Authentication, Reporting and Conformance builds on SPF and DKIM. It tells receiving servers what to do when a message fails the checks, and it sends you reports about who is sending mail using your domain.

DMARC has three policy levels:

None: Monitor only. Failing messages are still delivered, but you receive reports.

Quarantine: Failing messages are typically sent to spam

Reject: Failing messages are refused

The goal is to reach reject, which gives the strongest protection against impersonation of your domain.

A safe rollout plan

Moving too fast can block your own legitimate email, so go in steps.

Inventory your senders. List every service that sends email as your domain, including those that individual departments set up.

Publish SPF and enable DKIM for your main email platform and each other legitimate sender.

Publish DMARC at none with a reporting address, and collect reports for several weeks.

Read the reports to find legitimate senders that are failing, then fix them, and spot unauthorized sources.

Move to quarantine, optionally in stages using a percentage setting, and monitor for problems.

Move to reject when you are confident that legitimate mail passes.

Keep reviewing. Add new services to your records when they are introduced.

DMARC reports are formatted for machines. Use a reporting tool or your IT provider to read them in a useful form.

Benefits for a healthcare organization

Reduces the chance that criminals can impersonate your domain to families and vendors

Helps your legitimate mail reach inboxes, which matters for appointment notices and family communications

Gives you visibility into misuse of your domain

Supports your HIPAA safeguards for transmission security and workforce protection against malicious software

Some large email providers now expect bulk senders to authenticate mail, so setting this up also helps ordinary deliverability.

Common mistakes

Publishing multiple SPF records, which is invalid. A domain should have just one.

Forgetting third-party services that send on your behalf

Setting DMARC to reject too early and blocking real mail

Never reading the reports

Ignoring look-alike domains that are not covered, such as a name with one letter changed. Consider registering obvious variants and monitoring for new ones.

These standards protect your domain, but they do not stop all phishing aimed at your staff, which can come from other domains. Keep email filtering and staff training in place.

Checking where you stand

Free lookup tools can show your current SPF, DKIM and DMARC records. If you do not have a DMARC record at all, that is the first gap to close. UnityCare IT can review your email domain settings, identify unauthorized senders and manage the staged move to enforcement.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172