Stop domain spoofing and improve email trust. Here’s SPF, DKIM and DMARC explained simply for SMEs — plus the safest order to implement them.
A lot of email security advice focuses on filtering and training — both important — but there’s another layer that’s often overlooked: domain authentication. This is what helps other mail systems decide whether an email that claims to be from your domain is actually legitimate. If you don’t have these controls set up properly, attackers can spoof your domain more easily, and your genuine emails can be treated with more suspicion.
The three terms you’ll hear are SPF, DKIM and DMARC. They sound technical, but the concept is simple: you’re publishing rules that say who is allowed to send email on your behalf, and how receiving systems should handle messages that don’t match those rules. Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester — and we typically see quick wins when SMEs implement these in the right order and test carefully.
In plain English: SPF/DKIM/DMARC are settings that prove your emails are genuine and reduce spoofing and impersonation risk.
What each one does (simple explanation)
SPF (Sender Policy Framework)
SPF is a list of the systems allowed to send email for your domain.
If an email comes from somewhere not on the list, it’s suspicious.
DKIM (DomainKeys Identified Mail)
DKIM adds a cryptographic “signature” to your emails so recipients can verify the message wasn’t altered and genuinely came from your domain.
DMARC (Domain-based Message Authentication, Reporting & Conformance)
DMARC tells receiving systems what to do if SPF/DKIM checks fail — and it can send you reports so you can see what’s happening.
The safest order to implement (SME-friendly)
1) SPF first (but keep it accurate)
Identify all legitimate senders:
- Microsoft 365
- marketing platforms
- CRMs
- ticketing/support systems
- website forms
2) DKIM second
Turn on DKIM for your main email platform (often Microsoft 365) and any key senders that support it.
3) DMARC last (start gently)
Start with a monitoring stance (so you can see what would fail), then gradually tighten the policy once you’re confident legitimate senders are aligned.
Common mistakes SMEs make
- forgetting a legitimate sender (then emails start failing)
- multiple SPF records (this breaks SPF)
- jumping straight to strict DMARC without monitoring
- not reviewing DMARC reports at all
- assuming this replaces filtering and training (it doesn’t)
FAQ
Will SPF/DKIM/DMARC stop phishing completely?
No. It reduces spoofing and impersonation, but phishing can still come from lookalike domains and compromised accounts.
Can this affect deliverability?
Yes — usually positively when done correctly, but misconfiguration can cause delivery issues. Testing matters.
Is this relevant if we use Microsoft 365?
Absolutely. Microsoft 365 supports these controls and benefits from them.
If you want to reduce impersonation risk and improve email trust, we can implement SPF/DKIM/DMARC safely, verify all senders, and monitor reports so nothing breaks unexpectedly.
Get In Touch with us for a chat.