SPF, DKIM & DMARC Explained Simply for Small Business
September 26, 2026 · Elecrics Team
Why your business email needs protecting
Here's a scenario we see far too often on the South Shore: a customer gets an email that looks like it came from your company. Same name, maybe even your logo. It asks them to pay an invoice to a new bank account. They pay it — and the money is gone.
The scammer never touched your email account. They didn't need a password. They simply pretended to be you, because most business domains leave the front door wide open.
Three tools close that door: SPF, DKIM, and DMARC. They sound like alphabet soup, but the idea behind them is simple. This guide explains what each one does, why it matters, and how to get them set up — without the jargon.
The core problem: email trusts too easily
Email was invented decades ago, before anyone worried about fraud. By default, anyone can send a message claiming to be you@yourcompany.com. Nothing checks whether they're allowed to.
SPF, DKIM, and DMARC are three settings you add to your domain (the part after the @ in your email address). Together, they let receiving mail servers — like Gmail or Outlook — verify that an email really came from you. If it didn't, they can block it or flag it as suspicious.
Think of them as three layers of ID check at the door.
SPF: the guest list
SPF stands for Sender Policy Framework. In plain terms, it's a guest list of who's allowed to send email using your domain name.
When you set up SPF, you publish a short list of the mail services you actually use — for example, Microsoft 365, Google Workspace, your email marketing tool (like Mailchimp or Constant Contact), and maybe your accounting software that sends invoices.
When an email arrives claiming to be from your domain, the receiving server checks: "Is this sender on the approved list?" If yes, it passes. If a random server in another country tries to send as you, it fails.
The catch: SPF only checks the invisible "envelope" sender, not the name your customers actually see. A clever scammer can sometimes work around it. That's why you need the other two.
DKIM: the tamper-proof seal
DKIM stands for DomainKeys Identified Mail. Think of it as a wax seal on an envelope that proves the message is genuine and hasn't been altered.
When DKIM is on, your mail service adds an invisible digital signature to every message you send. The receiving server checks that signature against a key published on your domain. If they match, the email is verified as truly yours and untampered.
DKIM does two useful things:
- Confirms the message really came from your domain
- Confirms nobody changed the contents in transit
You don't see any of this — it happens in the background. But it's a strong signal to Gmail and Outlook that your email is trustworthy, which also helps your legitimate emails avoid the spam folder.
DMARC: the rulebook and the report
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. Don't worry about the name. DMARC does two jobs:
- It sets the rule for what happens when an email fails SPF and DKIM checks. You choose: do nothing, send it to spam, or reject it outright.
- It sends you reports showing who is sending email using your domain — including impostors.
DMARC is the piece that ties SPF and DKIM together and gives them teeth. Without it, a failed check might be ignored. With it, you tell the world: "If a message claiming to be from us doesn't pass, don't deliver it."
DMARC has three settings
- p=none — Monitor only. Nothing gets blocked, but you receive reports. This is where you start.
- p=quarantine — Suspicious messages go to the spam/junk folder.
- p=reject — Suspicious messages are refused entirely. This is the goal.
The smart approach is to start at none, watch the reports for a few weeks to make sure your legitimate email is passing, then tighten to quarantine and finally reject.
A quick real-world example
Say you run a 20-person contracting business in Weymouth. You use Microsoft 365 for email and QuickBooks to send invoices.
- SPF lists Microsoft 365 and QuickBooks as approved senders.
- DKIM signs every invoice and quote you send, proving it's genuine.
- DMARC tells Gmail and Outlook to reject any email pretending to be your company that isn't on the list.
Now when a scammer tries to email your customer a fake invoice from your domain, it bounces before it ever lands in the inbox. That single setup can prevent a costly fraud.
Why this also helps your email get delivered
Here's a bonus most people don't realize: Google and Microsoft now require proper email authentication for businesses that send in volume. If your SPF, DKIM, and DMARC aren't set up, your legitimate emails — quotes, newsletters, appointment reminders — are more likely to land in spam.
So this isn't only about security. It's about making sure the emails you want delivered actually arrive.
Your practical checklist
Here's what to work through, in order:
- List every service that sends email as your domain. Your email platform, marketing tools, accounting software, scheduling apps, CRM.
- Set up SPF with all those approved senders in one record. (There can only be one SPF record — don't create several.)
- Turn on DKIM in your email platform (Microsoft 365 and Google Workspace both support it) and any marketing tool you use.
- Publish a DMARC record starting at p=none. Include a reporting address so you can see what's happening.
- Review the reports for 2–4 weeks. Confirm all your real email is passing.
- Move DMARC to quarantine, then reject once you're confident nothing legitimate is being blocked.
- Recheck whenever you add a new tool that sends email on your behalf.
A few honest cautions
These records are edited in your domain's DNS settings — the same place your website address is managed. A typo can cause legitimate email to stop arriving, so measure twice and cut once. Moving DMARC to reject too fast, before your senders are all accounted for, is the most common mistake and can block your own invoices.
This is exactly the kind of behind-the-scenes work a managed IT provider handles: inventorying your senders, publishing the records correctly, and monitoring the reports so you never have to think about it.
Get a second set of eyes
Want to know whether your domain is already protected — or wide open? We're happy to take a look. Book a free 20-minute IT Fit Call at elecrics.com/book and we'll help you understand where your email security stands, no pressure and no jargon.