; ;

Email Security for SMEs: SPF, DKIM and DMARC in Plain English (and the Order to Implement Them)

Stop domain spoofing and improve email trust. Here’s SPF, DKIM and DMARC explained simply for SMEs — plus the safest order to implement them.

A lot of email security advice focuses on filtering and training — both important — but there’s another layer that’s often overlooked: domain authentication. This is what helps other mail systems decide whether an email that claims to be from your domain is actually legitimate. If you don’t have these controls set up properly, attackers can spoof your domain more easily, and your genuine emails can be treated with more suspicion.

The three terms you’ll hear are SPF, DKIM and DMARC. They sound technical, but the concept is simple: you’re publishing rules that say who is allowed to send email on your behalf, and how receiving systems should handle messages that don’t match those rules. Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester — and we typically see quick wins when SMEs implement these in the right order and test carefully.

In plain English: SPF/DKIM/DMARC are settings that prove your emails are genuine and reduce spoofing and impersonation risk.

What each one does (simple explanation)

SPF (Sender Policy Framework)

SPF is a list of the systems allowed to send email for your domain.
If an email comes from somewhere not on the list, it’s suspicious.

DKIM (DomainKeys Identified Mail)

DKIM adds a cryptographic “signature” to your emails so recipients can verify the message wasn’t altered and genuinely came from your domain.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

DMARC tells receiving systems what to do if SPF/DKIM checks fail — and it can send you reports so you can see what’s happening.

The safest order to implement (SME-friendly)

1) SPF first (but keep it accurate)

Identify all legitimate senders:

2) DKIM second

Turn on DKIM for your main email platform (often Microsoft 365) and any key senders that support it.

3) DMARC last (start gently)

Start with a monitoring stance (so you can see what would fail), then gradually tighten the policy once you’re confident legitimate senders are aligned.

Common mistakes SMEs make

FAQ

Will SPF/DKIM/DMARC stop phishing completely?

No. It reduces spoofing and impersonation, but phishing can still come from lookalike domains and compromised accounts.

Can this affect deliverability?

Yes — usually positively when done correctly, but misconfiguration can cause delivery issues. Testing matters.

Is this relevant if we use Microsoft 365?

Absolutely. Microsoft 365 supports these controls and benefits from them.

 

If you want to reduce impersonation risk and improve email trust, we can implement SPF/DKIM/DMARC safely, verify all senders, and monitor reports so nothing breaks unexpectedly. Get In Touch with us for a chat.

Morris - Morris Treger

Great service!

Jane - Blackjack's Mill Ltd

Problem sorted thanks to Mohammad :)

Laurence - Silva Timber Products Ltd

Quick and easy as everything was done for me.

Petra - Chelsea Psychology Clinic

The guy who helped me was very polite and patient. Also helped me resolve my issue quickly.

Sangita - Banana Tree

Excellent service - Thank You!

Tony - Minerva MC

I was contacted within a few minutes of reporting the issue and within 30 minutes all was sorted. I\'m not totally IT literate but Mohammad was patient and explained everything simply.

Fran - FMC Ltd

I had an issue with Spam email that Mohammed dealt with speedily and efficiently.

Paul - Silva Timber Ltd

Quick service, e-mailed and someone phoned me back within 15 minutes.

Andy - Adams Mitchell

Very quick response, cleared issue very quickly.