How to stop scammers sending email as your business

Anyone can put your address in the From line. How SPF, DKIM and DMARC stop that, in plain English, with the records to add and the order to add them.

email-security spf dkim dmarc small-business guide phishing

Nobody has to hack your email to send a message that looks like it came from you. Email was designed without any check on the From line, so a stranger can type your address there and press send. That is how a customer ends up paying an invoice with someone else's bank details on it. Three DNS records close that gap: SPF, DKIM and DMARC. They cost nothing, and plenty of small businesses have one of them at best. This is what each one does and the order to set them up in.

Check where you stand first

Our free email security grader reads the public records for your domain and gives you a letter grade with what's missing. It takes a few seconds, sends no email and needs no sign-up. Run it now, then again when you finish, so you know the change worked.

All three records are added in the same place: the DNS settings for your domain, at whoever you pay for the domain name (GoDaddy, Namecheap, Cloudflare, Squarespace and so on). If nobody knows who that is or what the login is, finding out is step zero.

SPF: the list of who may send as you

SPF is a single TXT record on your domain that lists the mail systems allowed to send email with your name on it. A receiving server checks the list, and mail from anywhere else fails.

If your email is Google Workspace, the record is:

v=spf1 include:_spf.google.com ~all

If it's Microsoft 365:

v=spf1 include:spf.protection.outlook.com -all

Two things break SPF more than anything else:

  • Two SPF records. You may only have one. If a second service needs adding, its include: goes inside the existing record. Two separate records count as none.
  • Too many includes. A receiving server will follow at most 10 lookups to read your record. Past that it gives up, and the record stops working without any warning. Remove services you no longer use.

DKIM: a signature on every message

DKIM has your mail provider sign each outgoing message, and publishes the key to check that signature in your DNS. A signed message proves it came from your system and wasn't altered on the way.

You switch it on at the mail provider, not at the domain host:

  • Google Workspace: Admin console, then Apps, Google Workspace, Gmail, Authenticate email. Generate the record, add the TXT record it shows you to your DNS, then come back and press Start authentication. People skip that last press all the time.
  • Microsoft 365: the Defender portal, under Email authentication settings, then DKIM. It gives you two CNAME records to add, then a toggle to turn signing on.

DMARC: what to do with the fakes

SPF and DKIM only produce a pass or a fail. DMARC is the record that tells other mail servers what to do about a fail, and it's the only one of the three that blocks anything. It is a TXT record at _dmarc.yourdomain.com.

Start with this:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

p=none means "change nothing, send me reports". The reports go to the address after rua=, so use a mailbox that exists. They arrive daily as attachments that are hard to read by eye, and a free DMARC report viewer will turn them into a list of who is sending mail as your domain.

Don't jump straight to reject

The reason to start at p=none is that you almost certainly send email from more places than you remember:

  • the invoicing or accounting software
  • the newsletter or marketing tool
  • the contact form on your website
  • the booking or point of sale system that emails receipts
  • the office copier that scans to email

Each of those needs to be in your SPF record or signing with DKIM, and each has a help page on how. Give it two to four weeks of reports, fix whatever shows up failing that is really yours, then change p=none to p=quarantine (fakes go to spam). When another couple of weeks pass quietly, change it to p=reject (fakes are refused outright).

Many businesses stop at p=none and assume the job is done. It isn't: monitoring blocks nothing, which is why our grader gives it about a third of the DMARC points.

Domains that never send email

If you own extra domains that only forward to your website, lock them too. They're the easiest ones to borrow because nobody is watching them. Two records say "this domain sends no email, refuse everything":

v=spf1 -all
v=DMARC1; p=reject

The first goes on the domain itself, the second at _dmarc.

It also gets your real email delivered

Since 2024, Gmail and Yahoo have required these records from anyone sending in bulk, and they treat mail from domains without them with more suspicion at any volume. If your quotes and invoices have been landing in customers' spam folders, missing records are the first thing to rule out.

What this won't stop

These records protect your exact domain. They do nothing about a lookalike (yourshop-billing.com), a message that uses your name with a random address behind it, or a real mailbox that someone has already signed in to. Those come down to two-step sign-in and people knowing what to look for, which is what one hour of security for people who don't do IT covers. And mailboxes that outlive the person who used them are their own problem: see the offboarding checklist.

If you'd rather not edit DNS yourself, your mail security records are part of the free written audit we do for small businesses in Seminole County and the Orlando area, along with the rest of your IT. The report is yours whether you sign or not.

Want this handled for you?

SentinelGrid Managed IT is in open beta: monitoring, remote support, patching and a real helpdesk for one flat monthly fee, plus a free infrastructure audit whether you sign or not.