Imagine a family member receives an email that appears to come from your facility's billing office, asking them to pay an invoice to a new account. The sender address looks right. The message is fake. Criminals can forge the from address on email far more easily than most people realize, unless the domain has specific protections in place.
Three settings, known as SPF, DKIM and DMARC, are the standard way to prevent this. They are not glamorous, but they protect your reputation, your residents' families and your own staff. Here is what they do, in plain English.
Email was designed without strong identity checks. Anyone can try to send a message claiming to be from your domain. Receiving mail servers have to decide whether to trust it. SPF, DKIM and DMARC give them rules to check.
SPF stands for Sender Policy Framework. It is a published list of the servers allowed to send email on behalf of your domain. When a message arrives claiming to come from your domain, the receiving server checks whether it came from an approved sender.
Common mistakes include:
Forgetting a legitimate sender, such as a marketing platform, billing system or scheduling tool
Listing too many services, which can break the record
Having more than one SPF record, which makes it invalid
DKIM stands for DomainKeys Identified Mail. Your email system adds a cryptographic signature to each outgoing message. The receiving server checks the signature against a public key published in your domain settings. If the message was altered along the way, or not sent by an authorized system, the check fails.
Each sending service, such as your main email platform or a newsletter tool, usually needs its own DKIM setup.
DMARC ties SPF and DKIM together. It tells receiving servers what to do with messages that fail the checks, and where to send reports about it. A DMARC policy can be set to:
None: Monitor only. Failing mail is still delivered, but you receive reports.
Quarantine: Failing mail is sent to spam.
Reject: Failing mail is refused.
The reports show who is sending mail using your domain, including legitimate services you forgot about and impostors.
Going straight to reject can block your own legitimate email if something is misconfigured. A careful approach looks like this:
Inventory senders. List every system that sends email as your domain: main email, billing, HR, newsletters, ticketing, and so on.
Publish SPF and enable DKIM for each sender.
Start DMARC at none with reporting turned on.
Review reports for a few weeks. Fix legitimate senders that fail.
Move to quarantine, then to reject once reports show clean results.
This can take weeks or months for organizations with many senders, but each step reduces risk.
You do not need to be an engineer. Free online lookup tools let you enter your domain and see whether SPF, DKIM and DMARC records exist. Your IT provider can also check them quickly. Look for:
An SPF record that exists and is valid
DKIM enabled for your main email system
A DMARC record, ideally with a policy beyond none
Reporting addresses that someone actually monitors
If you manage multiple domains, check them all, including old domains you still own. Unused domains can be abused too, and should have records that say no mail is sent from them.
Healthcare organizations are frequent targets for phishing and payment fraud. Strong email authentication helps protect:
Families who receive billing and admission communications
Referral partners and physicians who exchange information with you
Your staff, who may receive spoofed messages that appear to come from administrators
Your reputation and deliverability, so legitimate messages do not land in spam
Major mailbox providers also now expect senders to authenticate email, particularly for bulk mail.
These settings protect your domain from being forged. They do not stop phishing messages sent from other domains, including lookalike addresses. You still need email filtering, training and multi-factor authentication.
UnityCare IT reviews and configures SPF, DKIM and DMARC for healthcare organizations and monitors the reports. If you are not sure what your domain publishes today, we can check it and walk you through the next steps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172