Cybersecurity / Foxbyte Insights

SPF, DKIM and DMARC: what a business owner should ask

Foxbyte InsightsPublished Updated

Cybersecurity connects access, protection and recovery with business ownership.

SPF, DKIM and DMARC help receiving systems evaluate email-domain authenticity. They are useful controls, but they do not prove that a message’s business instruction is legitimate.

Understand the three questions

ControlPlain-language role
SPFIdentifies permitted sending sources for a domain used in the email envelope.
DKIMAdds a domain-linked signature that receiving systems can verify.
DMARCUses alignment with the visible From domain and states the domain owner’s handling policy.

Microsoft explains these controls as complementary parts of email authentication. Their configuration should be reviewed for the actual sending environment; passing authentication does not establish that an account has not been misused.

Inventory legitimate senders first

Your ordinary mailbox provider may not be the only system sending email for the business. A website form, invoicing platform, marketing service or support system may also send messages. Identify the owner and purpose of each legitimate source before tightening policy.

Include subdomains and important automated messages. An incomplete inventory can turn a security change into missing customer enquiries or failed operational notifications. Ask each provider for the current supported configuration rather than copying an unrelated example record.

Plan a controlled change

Record the current DNS and mail configuration, the intended change and the person authorised to make it. Agree a representative test set: ordinary mail, website enquiries and other important senders. Protect the existing domain and provider ownership throughout the work.

Use reporting and staged review appropriate to the environment before moving to a stricter handling policy. The exact sequence and records depend on the providers and current configuration. Avoid publishing a generic DNS string as though it fits every organisation.

Read reports as evidence, not a verdict

Authentication reports can reveal sources and alignment problems, but interpretation requires context. A source may be a legitimate service that has not been configured correctly or an unauthorised sender. Assign someone to investigate and maintain the inventory.

Likewise, a message passing checks can still contain a fraudulent payment instruction from a compromised legitimate account. Keep independent business verification for changes to sensitive records. Technical controls and approval procedures address different parts of the risk.

Ask for an acceptance record

  • The legitimate sending services reviewed.
  • The approved DNS or provider changes and their owner.
  • Representative delivery and authentication tests.
  • Known exceptions and who will resolve them.
  • The ongoing reporting and change process.

The useful deliverable is a maintained domain-sending picture and tested configuration. Three acronyms in a quotation are not enough to show that important business mail works or that future senders will be reviewed.

Sources and further reading

Put the decision into practice

List the services that send mail for your domain before requesting an email-security review.

Explore Microsoft 365 & Email Security Discuss the requirement by email
Talk to Us

Talk to Us

AI-assisted · Human help available

How can we help?

I’m Foxbyte’s AI assistant. Ask about a service, or talk to a person.

Scroll to Top