Imagine a family member receiving an email that appears to come from your administrator, asking them to pay an outstanding balance to a new account. Or a vendor receiving a message from your accounts payable address with new payment instructions. If your email domain is not properly protected, attackers can send messages that look exactly like they came from you.
Three email authentication standards, SPF, DKIM and DMARC, work together to prevent this. They are configured through DNS records, and they are one of the cheapest, most effective protections an organization can add. They also help your legitimate emails land in inboxes instead of spam folders.
Sender Policy Framework is a published list of the servers and services permitted to send email for your domain. When a message arrives, the receiving server checks whether it came from an approved sender. If your office email, your newsletter service, your billing platform and your website contact form all send mail as your domain, each needs to appear in the SPF record.
DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving server uses a public key published in your DNS to verify that the message really came from your domain and was not changed in transit. Each sending service typically has its own key.
Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving servers what to do with messages that fail SPF and DKIM alignment: do nothing and report (policy "none"), send to spam ("quarantine"), or reject outright ("reject"). It also sends you reports showing who is sending email using your domain, including both legitimate services you forgot about and impostors.
Fraud against families, vendors and staff. Spoofed messages that appear to come from your facility can damage trust and trick people into sending money or information.
Deliverability. Mailbox providers increasingly expect authenticated email, particularly for bulk senders. Unauthenticated mail is more likely to be filtered.
Brand and reputation. Attackers may impersonate a care organization to target its community.
Cyber insurance. Applications sometimes ask about email authentication.
The most common mistake is jumping straight to a strict policy and blocking your own legitimate mail. A phased approach avoids that.
Inventory every sender. List all the systems that send email as your domain: email platform, marketing tools, website forms, billing, scheduling, HR systems, ticketing tools and printers or scanners that email documents.
Publish SPF including all legitimate senders. Note that SPF has a limit on DNS lookups, so a long list of services can break it. Your IT team may need to streamline it.
Enable DKIM signing for your main email platform and for every third-party service that sends on your behalf.
Publish DMARC at p=none with an address to receive reports. This monitoring mode does not affect delivery.
Review reports for a few weeks. Identify legitimate sources that fail and fix them. Reports can be hard to read, so many organizations use a tool to summarize them.
Move to quarantine, often starting with a small percentage of messages, then increase.
Move to reject once you are confident that legitimate mail passes.
This typically takes weeks to a few months, depending on how many systems send as your domain.
Forgetting a third-party sender and blocking real messages, such as payroll notices or newsletters
Multiple SPF records on one domain, which invalidates SPF. There should be only one.
Skipping the domains you own but do not use. Park old and unused domains with a "no mail" SPF and a reject DMARC policy so they cannot be spoofed.
Setting DMARC to none and leaving it there forever, which reports abuse but does not prevent it
Not monitoring the reports once enabled
Free online lookup tools can show your SPF, DKIM and DMARC records. If a lookup shows no DMARC record, or one set to none with no plan to tighten it, you have room to improve. Your IT provider can also send a test message and review the headers to confirm that authentication passes.
These records protect your domain from being impersonated. They do not stop phishing emails arriving in your staff's inboxes from other domains. You still need spam filtering, link scanning, MFA and employee training.
UnityCare IT configures and monitors email authentication for healthcare organizations, including finding the forgotten systems that send mail on your behalf. If you are not sure whether your domain is protected, ask us to take a look.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034