Imagine a family member receives an email that appears to come from your facility's billing department asking for a payment. Or a vendor receives an invoice request that looks like it came from your administrator. If an attacker can send mail that appears to be from your domain, your reputation and your relationships are at risk, and your own legitimate emails may land in spam folders.
Three email authentication standards, SPF, DKIM and DMARC, help prevent this. They sound technical, but the concepts are straightforward.
Sender Policy Framework is a list, published in your domain's DNS records, of the servers allowed to send email on your behalf. When a receiving mail server gets a message claiming to be from your domain, it checks whether the sending server is on the list.
DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving server checks the signature using a public key in your DNS. A valid signature shows the message really came through your authorized system and was not modified in transit.
Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving servers how to handle messages that fail SPF and DKIM checks: do nothing and report, send to spam or reject outright. It also sends you reports showing who is sending email using your domain.
Fraud prevention: attackers impersonate administrators, billing offices and HR to request payments or payroll changes.
Deliverability: major mailbox providers increasingly expect authentication, and messages without it may be filtered.
Trust: families, referral partners and regulators should be able to rely on mail from your domain.
Visibility: DMARC reports reveal forgotten systems that send email for you, such as marketing tools, billing platforms or scanners.
Jumping straight to a strict policy can block legitimate mail. Follow stages.
List every system that sends email using your domain: your main email platform, website forms, newsletter tools, payroll or billing systems, EHR notification features, copier scan-to-email and any helpdesk software.
Add the authorized senders to your SPF record. Keep it within technical limits, since SPF allows a limited number of DNS lookups. Enable DKIM signing in each sending system.
Publish a DMARC record with a policy of none, which tells receivers to take no action but to send you reports. Review the reports for a few weeks to find legitimate senders that are failing and fix them.
Once legitimate mail passes reliably, tighten the policy to quarantine, which sends failures to spam, and finally to reject. Move gradually, such as applying the policy to a percentage of messages first.
Publishing multiple SPF records for one domain, which breaks the check
Forgetting third-party senders and then blocking their messages
Leaving DMARC on monitoring forever and never enforcing it
Not watching reports, which makes the setup pointless
Forgetting subdomains and old domains you no longer use but still own
These standards protect your domain from exact impersonation. They do not stop lookalike domains, such as one with a swapped letter, nor do they stop phishing sent to your staff from other domains. You still need email filtering, training and a reporting process.
DMARC reports arrive as dense XML files that few people enjoy reading. Use a reporting service or ask your IT provider to summarize them. Look for unfamiliar senders, repeated failures from systems you own and sudden changes in volume. A quick monthly review can reveal both forgotten legitimate senders and genuine impersonation attempts before they cause damage.
The changes are made in DNS and in your email systems, and mistakes can interrupt mail. Assign a responsible person or partner, make changes during business hours so problems are noticed quickly and keep a record of every sender you approve.
UnityCare IT can review your current records, identify gaps and manage the rollout so your legitimate email keeps flowing while impersonators are shut out.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172