SPF, DKIM and DMARC: Email Settings Worth Checking This Week

Imagine a family member receiving an email that appears to come from your administrator, asking them to pay an invoice to a new bank account. Without the right email authentication settings, criminals can send messages that look like they come from your domain. The messages may fool families, vendors and even your own staff.

Three standards, SPF, DKIM and DMARC, make it much harder to spoof your domain. They are also increasingly expected by large email providers. You do not need to be an engineer to understand them or to ask good questions.

What each setting does

SPF

Sender Policy Framework is a public record that lists which mail servers are allowed to send email for your domain. When a receiving server gets a message claiming to be from you, it checks whether the sending server is on the list.

DKIM

DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving server uses a public key published in your domain records to verify that the message was really sent by an authorized system and was not altered in transit.

DMARC

Domain-based Message Authentication, Reporting and Conformance ties them together. It tells receiving servers what to do when a message fails SPF and DKIM checks: do nothing and report, quarantine it, or reject it. It also sends you reports showing who is sending email using your domain.

Why this matters in healthcare

Spoofed messages can trick families and vendors into sending money or sharing information.

Attackers who impersonate your domain can damage your reputation.

Legitimate emails, such as billing notices and appointment reminders, are more likely to land in inboxes when authentication is set up properly.

Protecting your domain supports the Security Rule's expectations around protecting against malicious software and unauthorized access.

How to check where you stand

You can ask your IT provider, or use free online lookup tools to view your domain's records. Look for:

An SPF record that begins with v=spf1 and ends with a clear instruction such as a hard or soft fail.

A DKIM selector published for each system that sends email for you.

A DMARC record at _dmarc followed by your domain, with a policy.

If any of these are missing, you have a gap worth closing.

Common problems

Multiple SPF records. A domain should have only one, and extra records can cause failures.

Too many lookups in SPF, which can break the record.

Forgetting third-party senders such as billing software, newsletter tools, e-signature services or surveys.

Publishing DMARC with a policy of none and never moving forward.

Neglecting old or unused domains, which can also be spoofed.

Roll out DMARC in stages

Jumping straight to a strict policy can block legitimate mail, so roll out carefully:

Publish DMARC with a monitoring policy and collect reports.

Identify every system that sends mail on your behalf and fix its SPF and DKIM setup.

Move to a quarantine policy and watch for problems.

Move to a reject policy when you are confident that legitimate mail passes.

The process can take weeks or months depending on how many systems send email. The reports are the key tool, and many services can summarize them in readable form.

Do not forget the inbound side

Authentication protects your domain from being impersonated. It does not stop phishing aimed at your staff from other domains. Pair it with:

Email filtering and attachment scanning.

External sender warnings.

Multi-factor authentication on accounts.

Staff training and an easy way to report suspicious messages.

Secure the domain itself

Email records live in your domain's DNS, so protect the accounts that control it:

Use multi-factor authentication on your domain registrar and DNS provider.

Make sure the domain is registered to the organization, not an individual former employee.

Turn on auto-renewal and registrar lock.

Keep a list of who has access.

A short checklist

Do we have exactly one SPF record?

Is DKIM enabled for our main mail platform and other senders?

Is DMARC published, and is anyone reading the reports?

Do we know every service that sends email as our domain?

Are our registrar and DNS accounts protected with MFA?

How UnityCare IT can help

UnityCare IT configures and monitors email authentication for healthcare and senior-living clients. If you would like us to check your domain records, we can review them with you and explain what we find in plain language.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034