SPF, DKIM, and DMARC: What They Are and Why You Need Them

The ease of sending and receiving email makes it an attractive way to run scams like phishing attacks. One telltale mark of a phishing attack is the sender’s address not matching their purported domain; attacks that appear to come from legitimate email addresses are much more likely to fool the victim.

You can protect your organization’s email accounts from being compromised and used in phishing attacks by training your users to identify forged emails and use password managers, which won’t autofill a password on a malicious site. But how do you prevent bad guys from forging email that looks like it comes from inside your organization? You can’t, but you can reduce the chances that other email servers will accept it. In the process, you’ll enhance the deliverability of legitimate email from your domain.

The rest of this article is aimed at two types of readers. The first is the IT professional who needs an overview of email authentication technologies and pointers to helpful tools. For other readers, this article will give you an idea of what’s involved so you can talk more knowledgeably with your IT staff or better appreciate what they manage for you.

Whether your email is hosted at Microsoft 365 or Google Workspace, or managed by your Internet service provider or IT department, if your organization has its own domain for email addresses—yourname@yourcompany.com—you need to know about and set up three authentication technologies: SPF, DKIM, and DMARC:

  • SPF, which stands for Sender Policy Framework, lets you specify which servers and domains are allowed to send email for your organization. It allows receiving mail servers to verify that incoming messages from your organization are actually from you.
  • DKIM, or DomainKeys Internet Mail, adds a digital signature to every message sent from your organization. Receiving mail servers can use your public key to verify that messages actually came from you and were not changed in transit.
  • DMARC, which expands to Domain-based Message Authentication, Reporting, and Conformance, leverages SPF and DKIM to publish policies that tell receiving mail servers what to do with messages that fail authentication: deliver, quarantine, or reject them. A message fails DMARC authentication only if it fails both SPF and DKIM—only one is necessary for the message to pass DMARC’s checks.

These three authentication technologies exist inside DNS (Domain Name System) records. The primary use of DNS is to link your human-usable domain name with the underlying IP addresses of the servers that manage your Internet presence; for example, matching www.yourcompany.com with an IP address like 192.168.1.23. However, DNS can also contain TXT records with additional information about your domain—you configure SPF, DKIM, and DMARC using TXT records.

These TXT records must be carefully constructed to work correctly—an incorrect configuration could cause email failures. You could build them manually, but it’s safer to use a tool that asks you questions and spits out a correctly formatted TXT record for you to add to your DNS configuration. If all that sounds intimidating, work with your ISP or email service provider, or ask us for help. But here are the basics.

Tools abound for creating SPF, DKIM, and DMARC records, but we recommend those from DMARCLY and EasyDMARC. We’ll use DMARCLY for the examples here, and it provides a comprehensive explanation that’s worth reading if you want more depth.

SPF

SPF is the oldest of these technologies. To get started, all you need to do in DMARCLY’s SPF Generator tool is specify the names or IP addresses of servers that are allowed to send email from your domain. The mx (mail exchanger) and a radio buttons automatically add the servers listed in your DNS records, and anything you put in the Includes field will allow email sent from anything allowed by a third party that sends email on your behalf. It’s common to put Google, Amazon SES, SendGrid, or other systems there. The IPv4, IPv6, and Hostnames fields let you specify other allowed servers, but aren’t necessary.

The Policy menu is important—you can choose from Fail, SoftFail, and Neutral. Start with Neutral, which should allow messages to be accepted (it prefixes all in the TXT record with a ?). Then bump up to SoftFail (a tilde ~ prefix) to have messages accepted but marked. When you’re confident everything is working correctly, move to Fail, which uses a - prefix.

DKIM

Because it relies on public key cryptography, DKIM is significantly more complicated. Although DMARCLY’s DKIM Generator tool will generate the necessary public and private keys, that’s not helpful unless you have full control over your email server and know how to install the private key to sign all your outgoing email. It’s much more likely that you’ll use a tool managed by the company that hosts your email to create your keys. That tool will automatically install the private key and give you the necessary details to add to a TXT record in your DNS settings.

DMARC

Where SPF and DKIM are all about authenticating email messages, DMARC lets you say what happens when authentication fails. DMARCLY’s DMARC Generator tool makes it easy to generate your DMARC record. For Policy and Subdomain Policy, you can choose None, Quarantine, or Reject—those specify what will happen to messages that fail both SPF and DKIM authentication. Start with None to see what happens in your reporting, move to Quarantine, and if everything seems OK, end up at Reject.

To set up reporting, enter an email address in the Aggregate Email field, but don’t put a personal address there. DMARC reports are daily XML digests that aren’t human-readable, so they should be sent to a service that will parse them and provide you with a dashboard for exploring the problems. DMARCLY and EasyDMARC both offer dashboards, as does the Cloudflare service if you use it for DNS or other tasks. To start, you can leave DMARC’s Strict Alignment and Forensic Options blank.

Configuring DNS

Once you’ve generated your SPF, DKIM, and DMARC records, you have to configure them in your DNS settings. How you do that depends on your DNS host; we’ll show what it looks like Cloudflare. Other DNS hosts should be similar.

For each case, you’re creating a TXT record, but what goes in the Name and Content fields varies:

  • SPF: The name for an SPF record should be the @ character, signifying the root level of your domain. Paste the text that the SPF Generator tool created in the Content field. You can have only one SPF record for each domain, although you can set up separate SPF records for subdomains.
  • DKIM: You can have as many DKIM records as services that send email on your behalf, so the first part of the name can vary—we show example below. However, the ._domainkey part is required for each DKIM record. For the content, paste the text given to you by the email-sending service. Note that some email services may require you to create one or more CNAME records instead of a TXT record—just follow their instructions.
  • DMARC: For DMARC, the name must be _dmarc. Once again, you’ll paste the text given to you by the DMARC Generator tool in the Content field.

Reporting and Evaluation

After you set up SPF, DKIM, and DMARC, it’s essential to keep an eye on your email. If you’ve started with SPF in Neutral mode and DMARC in None, nothing should go wrong. You can look through the headers of test messages you send to verify. This DMARCLY article explains what to look for. If you’ve signed up for an aggregate reporting service, you’ll be able to see reports like this one from Cloudflare that show the percentage of email that passes each of the authentication technologies.

If everything looks good and most email passes, change SPF to SoftFail and DMARC to Quarantine. Make sure you can send email to some known personal addresses on Gmail, Yahoo, or iCloud. Also, tell people who send email from your domain to be on the alert if they don’t hear back from someone who typically replies quickly—if a misconfiguration is causing your email to be marked as spam, you want to know about that quickly. If you’re using a DMARC reporting service, look at those reports to see if any email services are sending a lot of messages that fail DMARC.

After you’ve run with those settings for a month or two, bump SPF up to Fail and DMARC to Reject. Continue to monitor your DMARC reporting and pay attention to any complaints from users about the messages they send not arriving.

That’s a lot, we know. Feel free to contact us if you need help with any step of the process.

(Featured image based on an original by iStock.com/Ole_CNX)


Social Media: To ensure phishers don’t forge email from your domain to use in their attacks on your organization and others, you must implement SPF, DKIM, and DMARC. We explain the basics, and we’re happy to help with the setup.

Similar Posts

  • Medgar Evers

    Medgar Evers (1925-1963) was an African-American civil rights activist whose murder drew national attention. Born in Mississippi, he served in World War II before going to work for the National Association for the Advancement of Colored People (NAACP). After applying to the segregated University of Mississippi Law School in 1954, he became the NAACP field secretary in Mississippi.

    As early as 1955, Evers activism made him the most visible civil rights leader in the state of Mississippi. As a result, he and his family were subjected to numerous threats and violent actions over the years, including a firebombing of their house in May 1963. At 12:40 a.m. on June 12, 1963, Evers was shot in the back in the driveway of his home in Jackson. He died less than a hour later at a nearby hospital. The accused killer Byron De La Beckwith initially escaped conviction.

    In December 1990, Beckwith was again indicted for the murder of Medgar Evers. After a number of appeals, the Mississippi Supreme Court finally ruled in favor of a third trial in April 1993. Ten months later, testimony began before a racially mixed jury of eight blacks and four whites. In February 1994, nearly 31 years after Evers’ death, Beckwith was convicted and sentenced to life in prison.

  • _Dear Friends,_

    I had a great trip up to Jasper, GA to pick up the 2003 Victory motorcycle. I took almost all two-lane roads and the weather cooperated although it was a bit chilly in the mornings. It got busier as I headed south in Florida but all in all it was a great way to spend the weekend.

    Small Dog Electronics is finishing up our 20th year in business and we are going to be changing out the 20-year anniversary banners and signs. Now that we are going to be 21 we are renewing our commitment to walking the walk as a socially responsible business. We feel that how we treat people, customers, employees, vendors or strangers is an equal measure of our success as to how we treat the planet and the profit we hope to make. Did you know that 100% of the electrical power for our S. Burlington store and about 85% of the power for our Waitsfield headquarters is generated from solar energy?

    When you form a “corporation”, if you tear down the word to its Latin base, it means to “form a body”. My high school latin teacher would be proud. As a body in society, a business has a bigger footprint than any individual. We have buildings, we consume resources, we generate waste and we have a huge impact on peoples lives. With that larger footprint comes a larger responsibility and that is the basis for our commitment to always measure our success by the triple bottom line of People, Planet and Profit.

    This week’s Kibbles & Bytes exclusive features the iPad mini 4. This model in Space Gray includes 64GB of storage and cellular capability. With the Retina display and Touch ID this incredibly thin and light iPad could be a complete solution. Because this model has cellular capability (cell contract required) you can use it anywhere where there is Wi-Fi or Cellular coverage. The iPad Mini 4 is my iPad of choice. I like the way it fits in one hand and is perfect for reading. It feels like you are holding a paperback book. This week, exclusively for Kibbles & Bytes readers we are offering the “iPad Mini 4 in Space Gray with AppleCare Plus”:http://www.smalldog.com/wag900002167 for a special price. AppleCare Plus for the iPad extends the 1-year warranty to 2-years and also provides for coverage for accidental damage (i.e. broken screen, etc.) for up to two incidents for a $49 deductible. It also extends the 90-days of free Apple technical support to 2-years. Normally, this bundle is $729.98 but we are giving Kibbles & Bytes readers the opportunity to save $40 on this bundle. You get the iPad mini 4 64GB Cellular model with AppleCare Plus for only “**$689.98!**”:http://www.smalldog.com/wag900002167

  • Audit How You Appear in Google Search

    Google has created a free service that lets you see what of your personal and professional information has been published on the Web….

  • The Best Apple-Related Gifts for 2021

    It may seem early to start thinking about the holiday shopping season, but with the global supply chain suffering pandemic-related slowdowns, there’s no…

  • CES Random Thoughts

    I talked a bit about the big Consumer Electronics Show last week and it is rapidly fading in the rearview mirror. I have gone to this show every year for the past decade or more. We actually exhibited our Chill Pill speakers and Hammerhead products at one CES but mostly I have come as a “buyer” to look for new products and trends.

    The Las Vegas convention center is a gigantic venue and the CES show spills out into the parking lot in front but also into some of the surrounding hotels and resorts. The Sands convention center was the second largest and housed some of the more interesting booths. This was the location for 3D printing, health care, fitness, home automation, robots and drones. There were sophisticated baby monitors, constant reporting thermometers, implanted blood glucose monitors and even a company that sold wireless sensors that monitor your soil’s nutrients and moisture. Home automation was huge with several competing standards vying to challenge Apple’s HomeKit. This year more companies were showing HomeKit compatible products so I think that Apple’s vision of your interconnected home is not far off.

    There are lots of ways to move from the Sands over to the LVCC but the best way is the free buses offered by CES. Cabs and the monorail are possible but the buses seem to be the fastest and they are free and comfortable. For me it was a great way to rest my weary feet for a few minutes before going to the other venue to continue walking through the crowds. At the convention center there are three main halls and the international pavilion over at the Westgate (formerly, Hilton). The Center hall is dominated by the big guys with gigantic booths for Samsung, Intel, LG and others. Those booths are usually mobbed so I quickly walked through to check out the TVs and moved on. The North Hall is where the iLounge was born and products for iPad and iPhone dominate that section. The biggest part of the North Hall, however, was the Auto section with concept cars being shown my several manufacturers including Ford, Audi, Mercedes and new electric car upstart Faraday.

    In the past several years the iLounge area and the international area were dominated by all sorts of cases for iPhones and iPads. This year there were a few in each section but cases were definitely not the dominate category. Over at the international pavilion there were lots of hover boards but unlike previous years, demos of the scooters were restricted to the booth area. Nevertheless, all sorts of scooters were being shown. I searched for interesting USB-C products and found some hubs that were not quite ready for prime time and a bunch of cables. I did see the USB-C displays that incorporate a hub and that could be the real solution for the office set-up for the USB-C equipped MacBook.

    I never seem to be able to coordinate my meetings by hall. It seems that I’ll have one meeting in the North Hall, the next in the South Hall and then another back at the hotel. I rode the buses a lot and got to see the whole show floor that way.

    I did find some interesting products that we may add to our offerings, and had some great meetings so it was worthwhile to visit this show that is a window on future technology.