Cybercriminals frequently impersonate legitimate companies by sending emails that appear to come from their domains.
SPF, DKIM and DMARC help receiving mail systems identify whether those emails are genuine.
SPF tells receiving mail servers which systems are authorised to send email on behalf of your domain.
For example, your organisation might authorise Microsoft 365 to send email.
DKIM adds a cryptographic signature to outgoing messages.
Receiving systems can verify that the email was authorised by the sending domain and was not modified during delivery.
DMARC builds on SPF and DKIM.
It allows the domain owner to specify how receiving systems should handle messages that fail authentication checks.
DMARC can also provide reporting that helps administrators identify unauthorised senders.
Overview
Without appropriate email authentication, attackers may have an easier time impersonating your company.
This could be used for
- Fake payment instructions
- CEO impersonation
- Supplier fraud
- Phishing customers
- Credential theft
Incorrectly configured email authentication can cause legitimate messages to fail.
Organisations using multiple systems such as Microsoft 365, CRM platforms, marketing services and ticketing systems need to account for each legitimate sender.
RepairIT can review and configure SPF, DKIM and DMARC for business domains and Microsoft 365 environments.
Need help with this? RepairIT can review your environment and recommend practical next steps for your business.