SPF, DKIM and DMARC Explained for Healthcare Administrators

Imagine a family member receives an email that appears to come from your facility's billing department asking for a payment. Or a vendor receives an invoice request that looks like it came from your administrator. If an attacker can send mail that appears to be from your domain, your reputation and your relationships are at risk, and your own legitimate emails may land in spam folders.

Three email authentication standards, SPF, DKIM and DMARC, help prevent this. They sound technical, but the concepts are straightforward.

The three pieces in plain English

SPF: who is allowed to send

Sender Policy Framework is a list, published in your domain's DNS records, of the servers allowed to send email on your behalf. When a receiving mail server gets a message claiming to be from your domain, it checks whether the sending server is on the list.

DKIM: is the message authentic and unaltered

DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving server checks the signature using a public key in your DNS. A valid signature shows the message really came through your authorized system and was not modified in transit.

DMARC: what to do when checks fail

Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving servers how to handle messages that fail SPF and DKIM checks: do nothing and report, send to spam or reject outright. It also sends you reports showing who is sending email using your domain.

Why it matters in healthcare

Fraud prevention: attackers impersonate administrators, billing offices and HR to request payments or payroll changes.

Deliverability: major mailbox providers increasingly expect authentication, and messages without it may be filtered.

Trust: families, referral partners and regulators should be able to rely on mail from your domain.

Visibility: DMARC reports reveal forgotten systems that send email for you, such as marketing tools, billing platforms or scanners.

A safe rollout plan

Jumping straight to a strict policy can block legitimate mail. Follow stages.

Step 1: Inventory your senders

List every system that sends email using your domain: your main email platform, website forms, newsletter tools, payroll or billing systems, EHR notification features, copier scan-to-email and any helpdesk software.

Step 2: Publish SPF and enable DKIM

Add the authorized senders to your SPF record. Keep it within technical limits, since SPF allows a limited number of DNS lookups. Enable DKIM signing in each sending system.

Step 3: Start DMARC in monitoring mode

Publish a DMARC record with a policy of none, which tells receivers to take no action but to send you reports. Review the reports for a few weeks to find legitimate senders that are failing and fix them.

Step 4: Move to quarantine, then reject

Once legitimate mail passes reliably, tighten the policy to quarantine, which sends failures to spam, and finally to reject. Move gradually, such as applying the policy to a percentage of messages first.

Common mistakes

Publishing multiple SPF records for one domain, which breaks the check

Forgetting third-party senders and then blocking their messages

Leaving DMARC on monitoring forever and never enforcing it

Not watching reports, which makes the setup pointless

Forgetting subdomains and old domains you no longer use but still own

What these do not do

These standards protect your domain from exact impersonation. They do not stop lookalike domains, such as one with a swapped letter, nor do they stop phishing sent to your staff from other domains. You still need email filtering, training and a reporting process.

Watch your reports

DMARC reports arrive as dense XML files that few people enjoy reading. Use a reporting service or ask your IT provider to summarize them. Look for unfamiliar senders, repeated failures from systems you own and sudden changes in volume. A quick monthly review can reveal both forgotten legitimate senders and genuine impersonation attempts before they cause damage.

Who should handle it

The changes are made in DNS and in your email systems, and mistakes can interrupt mail. Assign a responsible person or partner, make changes during business hours so problems are noticed quickly and keep a record of every sender you approve.

UnityCare IT can review your current records, identify gaps and manage the rollout so your legitimate email keeps flowing while impersonators are shut out.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172