SPF, DKIM and DMARC help stop criminals spoofing your domain. Here’s what each one does, what “good” looks like, and how SMEs roll it out safely.
If you’ve ever had a customer say “I got an email from you asking for payment details” — when you didn’t send it — you’ve seen the real-world impact of email spoofing. Attackers can impersonate your domain to make phishing emails look legitimate. Even if your internal security is strong, spoofing damages trust, puts customers at risk, and can lead to invoice fraud.
SPF, DKIM and DMARC are the core controls that help prevent this. They’re not new, but many SMEs still don’t have them set up properly (or they’re set up in a “half-finished” way that doesn’t actually block spoofing).
Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester — and email authentication is one of the most practical, high-impact security improvements you can make because it protects your brand as well as your users.
In plain English: SPF, DKIM and DMARC are settings that tell the world which systems are allowed to send email “as your domain”, and what to do when something doesn’t match.
What each control does (simple explanation)
SPF (Sender Policy Framework)
A list of approved senders for your domain. It helps receiving mail servers check whether the sending system is allowed.
DKIM (DomainKeys Identified Mail)
A cryptographic “signature” added to outgoing email. It proves the message hasn’t been tampered with and really came from an authorised system.
DMARC
The policy layer. It tells receiving servers what to do if SPF/DKIM checks fail (monitor, quarantine, or reject) and gives you reporting.
What “good” looks like for SMEs
- SPF includes only legitimate senders (and isn’t overloaded)
- DKIM enabled for your main mail platform and key third-party senders
- DMARC starts in monitoring, then moves to enforcement
- you review DMARC reports so you don’t accidentally block legitimate systems
Common mistakes
- setting DMARC to “reject” without checking all senders first
- forgetting marketing platforms, CRMs, ticketing tools, or payroll systems that send email
- SPF record too long or includes risky “allow all” patterns
- no ongoing review, so new senders break deliverability later
FAQ
Will this stop all phishing?
No — but it significantly reduces domain spoofing, which is one of the most damaging types because it impersonates your brand.
Can this affect deliverability?
Yes, if implemented badly. Done properly, it usually improves trust and deliverability over time.
If you want to protect your domain from spoofing without disrupting legitimate email, we can
audit your current setup and implement SPF/DKIM/DMARC in a safe, staged way.