Imagine a family member receives an email that appears to come from your administrator, asking them to pay an invoice to a new bank account. Or a vendor receives a message that looks like it came from your accounts payable team. If your email domain is not properly protected, criminals can forge your address with surprising ease. Three technical standards, SPF, DKIM and DMARC, exist to prevent this. They sound intimidating, but their purpose is simple, and setting them up is a one-time project that pays off continuously.
The original email system had no built-in way to confirm that a message claiming to be from your domain was truly sent by you. Anyone can type any address in the from field. That is why spoofing, phishing and business email compromise scams so often use a trusted name. SPF, DKIM and DMARC add verification layers that receiving mail servers can check.
Sender Policy Framework (SPF) is a list, published in your domain's DNS records, of the servers and services authorized to send email on behalf of your domain. When a message arrives, the receiving server checks whether it came from one of those sources.
Things to remember:
Include every legitimate sender, such as your email platform, your newsletter service, your billing system, your website contact form and your helpdesk tool. Missing one can cause real mail to fail.
A domain should have only one SPF record.
SPF has a limit on how many lookups it can perform, so a messy record can silently fail.
DomainKeys Identified Mail (DKIM) adds a digital signature to outgoing messages. The receiving server uses a public key published in your DNS to verify that the message really came from your domain and was not changed in transit. Each sending service you use may need its own DKIM setup, and your IT provider or email vendor usually provides the records to publish.
Domain-based Message Authentication, Reporting and Conformance (DMARC) ties SPF and DKIM together. It tells receiving servers what to do with messages that fail the checks, and it sends you reports about who is sending email using your domain.
DMARC has three policy levels:
None (monitor): do nothing special, but send reports. This is where you start.
Quarantine: send failing messages to spam.
Reject: refuse failing messages entirely.
The goal is to reach reject, which gives the strongest protection against someone forging your domain.
Jumping straight to reject can block your own legitimate mail. A careful path looks like this:
Inventory every system that sends email as your domain. Ask each department. Business offices, marketing, therapy contractors and software tools often send mail you do not know about.
Publish or fix SPF to include them.
Enable DKIM for each sending service.
Publish a DMARC record at the none policy with a reporting address, then review reports for a few weeks. Reports show failing sources, both legitimate ones you forgot and fraudulent ones.
Fix legitimate sources that fail.
Move to quarantine, then to reject, once reports are clean. Consider ramping up gradually, applying the policy to a percentage of mail first.
Keep monitoring. New tools and vendors will appear over time.
Deliverability: major mailbox providers expect authentication. Properly configured domains are less likely to land in spam, which matters for communications with families, referral sources and payers.
Trust: protecting your domain protects residents' families from scams that use your name.
Insurance and compliance: cyber insurance applications increasingly ask about email authentication.
SPF, DKIM and DMARC protect your domain from being impersonated. They do not stop phishing messages sent to you from other domains, including look-alike domains with a swapped letter. You still need filtering, staff training and verification procedures for payment changes.
Free tools can look up a domain's SPF, DKIM and DMARC records and show whether they are present and valid. Ask your IT provider for a report on your current status, and for a plan with dates if the policy is still at none.
UnityCare IT configures and monitors email authentication for healthcare and senior-living domains, including websites and third-party senders. If you are not sure whether your domain can be spoofed today, we can check it and tell you plainly.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172