Email Security Basics: SPF, DKIM & DMARC Explained Simply
July 28, 2026 · Elecrics Team
Why your email needs protecting in the first place
Here's an uncomfortable truth: by default, anyone on the internet can send an email that looks like it came from your company. They can put your domain (the part after the @ in your email address, like yourbusiness.com) in the "From" line, and to the person receiving it, it appears completely legitimate.
Scammers use this trick constantly. They'll pretend to be you — the owner — and email your bookkeeper asking to wire money or buy gift cards. They'll pose as your company and email your customers with a fake invoice. This is called spoofing, and it's one of the most common ways small businesses in Massachusetts get burned.
The good news: there are three settings you can turn on to make spoofing your domain far harder. They're called SPF, DKIM, and DMARC. They sound intimidating, but the concepts are simple. Let's walk through them without the jargon.
The three protections, in plain English
Think of these three as a set of security guards for outgoing email that carries your company's name.
SPF — the guest list
SPF (Sender Policy Framework) is basically a guest list. It's a record you publish that says, "These are the mail servers allowed to send email using my domain."
When a receiving server (like Gmail or Outlook) gets a message claiming to be from yourbusiness.com, it checks your SPF list. If the message came from a server that's on the list, great. If not, that's a red flag.
- Example: If you use Microsoft 365 to send email, your SPF record tells the world, "Only Microsoft's servers are authorized to send as us."
- Watch out: If you also send email through other tools — a marketing platform like Mailchimp, an accounting app that emails invoices, or a scheduling system — each of those needs to be added to the list. Miss one, and its emails may land in spam.
DKIM — the tamper-proof seal
DKIM (DomainKeys Identified Mail) adds an invisible digital signature to each email you send. Think of it like a wax seal on an envelope. The receiving server can verify that the seal is genuine and that the message wasn't altered in transit.
DKIM proves two things:
- The email really did come from your domain.
- Nobody tampered with the contents along the way.
You don't see any of this — it happens in the background — but it gives receiving servers strong evidence that your mail is the real deal.
DMARC — the rulebook and the report
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the first two together. It does two important jobs:
- It sets the rule. DMARC tells receiving servers what to do with email that fails the SPF and DKIM checks — ignore the problem, send it to spam, or reject it outright.
- It sends you reports. DMARC can email you summaries showing who is sending mail using your domain. This is how you catch scammers impersonating you — and how you spot legitimate services you forgot to authorize.
Without DMARC, SPF and DKIM are like having a guest list and a wax seal but no instructions on what to do when someone shows up without either.
How they work together — a quick analogy
Imagine your company sends a letter:
- SPF confirms the letter came from an authorized mailroom.
- DKIM is the tamper-proof seal proving it wasn't opened and changed.
- DMARC is the policy that says, "If a letter arrives without a valid mailroom stamp and no proper seal, throw it out — and send me a log of everything."
Turn on all three and you dramatically reduce the odds of someone successfully faking your company's email.
What happens if you skip this
Skipping these settings creates two real risks for a small business:
- Your name gets used against your customers and staff. A convincing fake invoice or a "quick favor" email from the "boss" is much easier to pull off when your domain is unprotected.
- Your real email stops getting delivered. Gmail, Yahoo, and Microsoft have all tightened their rules. Companies that send email without proper authentication increasingly find their legitimate messages landing in spam — or bouncing entirely. That means missed quotes, invoices, and customer replies.
A practical checklist
You don't need to be technical to make sure this is handled. Use this list:
- Find out where your email lives. Most small businesses use Microsoft 365 or Google Workspace. Know which one you have.
- List every tool that sends email as you. Marketing platforms, CRM, invoicing/accounting software, appointment reminders, e-commerce. Write them all down.
- Confirm SPF is set up and includes all of those tools.
- Confirm DKIM is enabled for your email platform (and for major sending tools that support it).
- Set up DMARC — start in "monitoring" mode so you can see the reports without blocking anything, then tighten the policy once you're confident legitimate mail passes.
- Review the DMARC reports for a few weeks to catch anything unexpected.
- Re-check whenever you add a new tool that sends email on your behalf.
One important caution
Don't rush straight to the strictest DMARC setting. If you flip it to "reject" before every legitimate sender is properly authorized, you can accidentally block your own emails — including the invoices and quotes your business depends on. Start in monitoring mode, review the reports, then tighten gradually. This step-by-step rollout is exactly where people get tripped up going it alone.
Where a bit of help pays off
The concepts here are simple, but the setup involves editing your domain's DNS records — the technical settings that route your website and email. A small typo can knock out your email delivery, so it's worth getting right the first time. This is routine work for a managed IT provider; it's the kind of quiet, behind-the-scenes protection we handle for South Shore businesses so owners don't have to think about it.
If you're not sure whether your email is properly protected — or if you've never heard of these settings until now — that's a common and fixable situation. We'd be glad to take a look. You can book a free 20-minute IT Fit Call at https://elecrics.com/book, and we'll help you understand where you stand, no pressure and no obligation.