Short answer:SPF, DKIM and DMARC are three technical settings for your email domain that together prevent fraudsters from sending emails in your company's name. SPF tells who can send, DKIM stamps the email as authentic and DMARC decides what happens to emails that don't pass the check.
Why do I need to care about this?
Email was once built without built-in anti-forgery protection. This means that anyone can, in theory, send an email that appears to be frominfo@dittforetag.se- without having access to your email. Fraudsters take advantage of this to trick your customers and employees into clicking on fake invoices or giving out passwords. It is called phishing and domain falsification (spoofing).
SPF, DKIM and DMARC are the answer to that problem. Think of them as three layers of ID protection for your email address.
What does SPF do?
SPF (Sender Policy Framework) is a list of which servers have the right to send email on your behalf. When an email comes in, the recipient's system can look up the list and check: did this come from an approved sender?
Parable:SPF is like a guest list at a party. If you are not on the list, you will not enter.
What does DKIM do?
DKIM (DomainKeys Identified Mail) puts an invisible digital signature on every email you send. The recipient can check the signature and see two things: that the email really comes from your domain, and that no one has changed the content along the way.
Parable:DKIM is like a wax seal on a letter. If the seal is complete and genuine, the recipient knows that the letter has not been opened and tampered with.
What does DMARC do?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the boss that ties the other two together. It says to receiving systems:if an email claims to be from us but doesn't pass SPF or DKIM - what should you do?You can choose to let such emails pass through, end up in the spam folder or be blocked completely.
DMARC can also send you reports, so you can see if someone is trying to abuse your domain.
Parable:DMARC is the security guard that has instructions on exactly what should happen to anyone who is neither on the guest list nor has a valid seal.
The three are needed together. SPF and DKIM do the checking, but it's DMARC that actually determines consistency – and gives you visibility into what's going on.
What if I don't have them?
- Your emails end up in spam more often.Major email providers such as Google and Microsoft trust senders without these settings less.
- Fraudsters can send emails in your name.It damages both your customers and your reputation.
- You don't notice it's going on.Without DMARC reports, you are blind to abuse.
How do I set it up?
In practical terms, SPF, DKIM and DMARC are entered as so-called DNS records - small lines of text with whoever manages your domain. It's not a big deal technically, but it's easy to get it wrong, and an incorrect SPF can actually cause your own emails to bounce. Therefore, it pays to do it methodically:
- Map which services send you emails– email provider, newsletter tool, booking system and so on.
- Add SPF and DKIMfor each of them.
- Begin DMARC cautiously- with just monitoring - and sharpen only when you see that everything is working.
Do you want it safe and right from the start?
This is exactly what ZORC helps companies with when we protect company data and emails. We set up SPF, DKIM and DMARC correctly so that your emails arrive - and so that no one can send in your name. Get in touch with ZORC, and we'll go over how your email domain is doing today and what needs to be fixed.