If you have ever received an email that appeared to come from your own administrator but did not, you have seen spoofing. Because email was designed without strong identity checks, anyone can type any sender address. Three technical standards, SPF, DKIM and DMARC, help receiving mail systems decide whether a message really came from your domain. They also protect your residents' families, vendors and partners from fake messages that use your name.
You do not need to configure these yourself, but administrators should understand them enough to ask the right questions.
Sender Policy Framework is a public record that lists which servers are allowed to send email for your domain. When a message arrives, the receiving system checks whether the sending server is on your list. If your email comes from a hosted email platform, a newsletter service and a billing system, all three should be on the list.
DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving system uses a public key published in your domain records to verify that the message really came from you and was not altered along the way.
Domain-based Message Authentication, Reporting and Conformance builds on the other two. It tells receivers what to do when a message fails the checks, and sends you reports about who is sending email using your domain. There are three policy levels:
none: Monitor only. Failing messages are delivered, but you receive reports.
quarantine: Failing messages are sent to spam.
reject: Failing messages are blocked.
The goal for most organizations is to move gradually to reject.
Fewer successful impersonations. Criminals pretending to be your administrator or business office have a harder time reaching other people with your domain name.
Better delivery of legitimate email. Large email providers have increasingly expected authentication, especially from organizations that send in volume, so properly configured domains are more likely to reach inboxes.
Visibility. DMARC reports reveal services sending email as you, including forgotten or unauthorized ones.
Reputation. Families and partners can trust messages from your domain.
Insurance. Cyber insurance applications frequently ask whether these records are in place.
Turning DMARC straight to reject can block your own legitimate email if some system was missed. A staged approach prevents that.
List every service that sends email using your domain: your main email platform, the website contact form, newsletter tools, payroll or billing systems, appointment reminders, scanners and copiers, and your helpdesk or ticketing system.
Create an SPF record that includes each legitimate sender. Be aware there are technical limits on the length and number of lookups, so keep it tidy.
Turn on signing for each sending service, publishing the keys in your domain records.
Start with a policy of none, with a mailbox or reporting service to receive reports. Review them for a few weeks to confirm which sources pass and fail.
Add or correct any legitimate senders that fail. Contact vendors that send on your behalf and ask them to support DKIM for your domain.
Once legitimate email consistently passes, tighten the policy in stages, watching reports at each step.
When you add or change a service that sends email, update the records. Review reports regularly.
Multi-factor authentication on all mailboxes
Email filtering that scans links and attachments
Warning banners on messages from outside the organization
Lookalike domain monitoring, since criminals may register a similar name
Staff training on suspicious messages
Authentication records stop exact-domain spoofing. They do not stop a criminal from using a similar domain or compromising a real account, so layered protection is still needed.
Do we have SPF, DKIM and DMARC configured for all of our domains, including ones we do not use for email?
What is our current DMARC policy?
Who reads the DMARC reports?
Which services send email on our behalf?
Do we have a plan to reach a stricter policy?
If you own domains that never send email, publish records that say so. Criminals like to abuse forgotten domains that lack protection.
UnityCare IT configures and monitors email authentication for healthcare organizations, including the staged move to a strict DMARC policy. If you are not sure what your domain publishes today, we can check it for you.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034