SPF, DKIM, and DMARC Explained for Small Businesses
August 27, 2026 · Elecrics Team
Why your business email needs three little settings
If you run a 10- or 30-person company on the South Shore, your email address is part of your reputation. When a client in Quincy gets a message that looks like it's from you, they trust it. That trust is exactly what scammers try to exploit.
Email spoofing is when someone sends a message that appears to come from your domain (the part after the @ in your address, like yourcompany.com). They can make it look like your bookkeeper is asking to change bank details, or like you're asking an employee to buy gift cards. The recipient sees your name, not the scammer's.
The good news: there are three settings that dramatically reduce this risk. They're called SPF, DKIM, and DMARC. They sound like alphabet soup, but the ideas behind them are simple. This guide explains each one without the jargon and gives you a checklist to get them in place.
The short version
Think of it like sending a physical letter:
- SPF is the list of post offices allowed to mail letters on your behalf.
- DKIM is a tamper-proof wax seal proving the letter wasn't altered in transit.
- DMARC is your instruction to the receiving mailroom: "If a letter claims to be from me but fails these checks, here's what to do with it."
Together, they tell the world's email systems how to spot a fake pretending to be you.
SPF: who's allowed to send email as you
SPF stands for Sender Policy Framework. It's a short list, stored with your domain, of the mail servers permitted to send email using your address.
When your business uses several tools — Microsoft 365 or Google Workspace for daily email, plus something like a marketing platform, your booking software, or an invoicing app — each of those services sends email on your behalf. SPF lists all of them.
Here's why it matters: when a receiving server (say, a client's inbox) gets a message claiming to be from your domain, it checks your SPF list. If the sending server isn't on the list, that's a red flag.
Common mistake: businesses add SPF but forget to include a tool they actually use. Then their legitimate invoices or newsletters start landing in spam. Every service that sends email as you needs to be in your SPF record.
DKIM: proof the message wasn't tampered with
DKIM stands for DomainKeys Identified Mail. It adds an invisible digital signature to every email you send — like a wax seal on an envelope.
When the message arrives, the receiving server checks the seal. If it matches, the server knows two things: the message genuinely came from your domain, and nobody changed it along the way. If someone tried to alter the content, the seal breaks and the check fails.
DKIM works quietly in the background. Your recipients never see it, but it's doing steady work to prove your email is authentic.
DMARC: the instructions that tie it all together
SPF and DKIM do the checking. DMARC — Domain-based Message Authentication, Reporting, and Conformance — decides what happens next.
Without DMARC, a message can fail SPF and DKIM checks and still get delivered, because the receiving server has no instructions from you. DMARC fills that gap. It lets you say one of three things:
- None — "Just watch and report to me, but deliver everything for now." A safe starting point while you check your setup.
- Quarantine — "If a message fails, send it to the spam folder."
- Reject — "If a message fails, don't deliver it at all." The strongest protection.
DMARC also sends you reports showing who's sending email using your domain — including impersonators. That visibility is genuinely useful.
The right approach is gradual. You start at none to gather data and confirm your real email still flows. Once you're confident, you move to quarantine, then reject. Jumping straight to reject before your SPF and DKIM are correct can block your own legitimate email — a painful mistake right before you send out client invoices.
Two problems these settings solve
1. Impersonation. With DMARC set to reject, a scammer who tries to send "from" your domain gets their fake message blocked or buried in spam before your client ever sees it.
2. Deliverability. Big providers like Google and Microsoft increasingly favor senders who authenticate properly. Businesses without these settings are more likely to have their real emails land in spam. So this isn't only security — it helps your important messages actually reach the inbox.
A practical checklist
You don't need to memorize the technical details. You just need to know whether this is handled. Here's how to check:
- [ ] Confirm you have SPF. It should list every service that sends email as your business — your main email platform plus any marketing, booking, or invoicing tools.
- [ ] Confirm DKIM is turned on in your email platform (Microsoft 365 and Google Workspace both support it).
- [ ] Confirm DMARC exists and note whether it's set to none, quarantine, or reject.
- [ ] Review DMARC reports to see who's sending as you.
- [ ] Move toward reject over time, once you're sure legitimate email passes.
- [ ] Update your records whenever you add a new email-sending tool.
A free way to get a rough picture: search for an online "DMARC checker" or "SPF checker," enter your domain, and see what comes back. If it says no DMARC record is found, that's a gap worth closing.
Where this fits in your bigger email security picture
SPF, DKIM, and DMARC stop others from pretending to be you. They don't stop phishing emails from arriving to you — that's a separate layer involving spam filtering and training your team to spot red flags. Think of email security as several locks working together: authentication, filtering, multi-factor login, and an alert staff.
The reason many small businesses skip these settings is simple: they live in your domain's DNS records (the internet's address book), which is unfamiliar territory. A small typo can cause real problems, which is why this is one of the areas a managed IT provider typically sets up and monitors so you don't have to touch it.
Getting it done
Setting up all three usually isn't expensive — often it's more about doing it carefully in the right order than about cost. The value is in getting it right so you gain the protection without accidentally blocking your own email.
If you'd like a straightforward check on where your email security stands, Elecrics offers a free 20-minute IT Fit Call. We're based in Braintree and work with small and mid-sized businesses across Massachusetts and the South Shore. Book yours at https://elecrics.com/book and we'll help you sort out what's protected and what isn't — no pressure, no jargon.