SPF, DKIM and DMARC Explained for Healthcare Offices

Imagine a family member receives an email that appears to come from your facility's billing office, asking them to pay an invoice to a new account. The sender address looks right. The message is fake. Criminals can forge the from address on email far more easily than most people realize, unless the domain has specific protections in place.

Three settings, known as SPF, DKIM and DMARC, are the standard way to prevent this. They are not glamorous, but they protect your reputation, your residents' families and your own staff. Here is what they do, in plain English.

The Problem They Solve

Email was designed without strong identity checks. Anyone can try to send a message claiming to be from your domain. Receiving mail servers have to decide whether to trust it. SPF, DKIM and DMARC give them rules to check.

SPF: Who May Send Mail for You

SPF stands for Sender Policy Framework. It is a published list of the servers allowed to send email on behalf of your domain. When a message arrives claiming to come from your domain, the receiving server checks whether it came from an approved sender.

Common mistakes include:

Forgetting a legitimate sender, such as a marketing platform, billing system or scheduling tool

Listing too many services, which can break the record

Having more than one SPF record, which makes it invalid

DKIM: A Digital Signature

DKIM stands for DomainKeys Identified Mail. Your email system adds a cryptographic signature to each outgoing message. The receiving server checks the signature against a public key published in your domain settings. If the message was altered along the way, or not sent by an authorized system, the check fails.

Each sending service, such as your main email platform or a newsletter tool, usually needs its own DKIM setup.

DMARC: What to Do When Checks Fail

DMARC ties SPF and DKIM together. It tells receiving servers what to do with messages that fail the checks, and where to send reports about it. A DMARC policy can be set to:

None: Monitor only. Failing mail is still delivered, but you receive reports.

Quarantine: Failing mail is sent to spam.

Reject: Failing mail is refused.

The reports show who is sending mail using your domain, including legitimate services you forgot about and impostors.

A Safe Way to Roll It Out

Going straight to reject can block your own legitimate email if something is misconfigured. A careful approach looks like this:

Inventory senders. List every system that sends email as your domain: main email, billing, HR, newsletters, ticketing, and so on.

Publish SPF and enable DKIM for each sender.

Start DMARC at none with reporting turned on.

Review reports for a few weeks. Fix legitimate senders that fail.

Move to quarantine, then to reject once reports show clean results.

This can take weeks or months for organizations with many senders, but each step reduces risk.

How to Check Where You Stand

You do not need to be an engineer. Free online lookup tools let you enter your domain and see whether SPF, DKIM and DMARC records exist. Your IT provider can also check them quickly. Look for:

An SPF record that exists and is valid

DKIM enabled for your main email system

A DMARC record, ideally with a policy beyond none

Reporting addresses that someone actually monitors

If you manage multiple domains, check them all, including old domains you still own. Unused domains can be abused too, and should have records that say no mail is sent from them.

Why This Matters for Healthcare

Healthcare organizations are frequent targets for phishing and payment fraud. Strong email authentication helps protect:

Families who receive billing and admission communications

Referral partners and physicians who exchange information with you

Your staff, who may receive spoofed messages that appear to come from administrators

Your reputation and deliverability, so legitimate messages do not land in spam

Major mailbox providers also now expect senders to authenticate email, particularly for bulk mail.

Limits to Remember

These settings protect your domain from being forged. They do not stop phishing messages sent from other domains, including lookalike addresses. You still need email filtering, training and multi-factor authentication.

How UnityCare IT Can Help

UnityCare IT reviews and configures SPF, DKIM and DMARC for healthcare organizations and monitors the reports. If you are not sure what your domain publishes today, we can check it and walk you through the next steps.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172