How SPF, DKIM and DMARC Protect Small Business Email from Spoofing

Your business email domain is part of your identity. When a customer sees a message from accounts@yourcompany.co.uk, they assume it came from your business. Criminals can sometimes forge that visible sender address without signing in to the mailbox. That is known as email spoofing.

Blog Main Image

How SPF, DKIM and DMARC Protect Small Business Email from Spoofing

Your business email domain is part of your identity. When a customer sees a message from accounts@yourcompany.co.uk, they assume it came from your business. Criminals can sometimes forge that visible sender address without signing in to the mailbox. That is known as email spoofing.

Spoofing is often used for fake invoice requests, payment changes or links that lead to a malicious website. It can also damage trust: a customer may believe your business sent something unsafe. For a small firm in Bolton, Bury or elsewhere in the North West, one convincing message can create financial loss and a long day of disruption.

The good news is that there is a practical domain-level check that makes this harder. It is the combination of SPF, DKIM and DMARC.

The three email checks in plain English

SPF: who is allowed to send?

SPF (Sender Policy Framework) is an approved-sender list published for your domain. It tells receiving email systems which services are allowed to send messages on your behalf — for example Microsoft 365, Google Workspace, your website form or your mailing platform.

If a message claims to be from your domain but comes from a server that is not on the list, the receiving system has a reason to treat it with suspicion.

SPF is useful, but it is not a complete solution. A business can have a correct SPF record and still need the other two controls.

DKIM: has the message been tampered with?

DKIM (DomainKeys Identified Mail) adds a digital signature to outgoing messages. The receiving system checks that signature using information published in your domain records.

In plain English, DKIM helps answer: "Did an approved sending service sign this message, and has it changed on the way?" It is a tamper check, not a guarantee that every message is safe.

DMARC: what should happen when a check fails?

DMARC (Domain-based Message Authentication, Reporting and Conformance) connects the checks to the sender people see in the From line. It lets you publish a policy for messages that fail authentication:

  • monitor the results and receive reports
  • place suspicious messages in spam or quarantine
  • reject messages that clearly fail

DMARC also helps you see which systems are sending mail that claims to be from your domain. That visibility is valuable because many businesses have forgotten about an old newsletter tool, website plug-in or CRM integration.

Why Microsoft 365 or Google Workspace does not remove the need

Microsoft 365 and Google Workspace include strong email security, but they do not automatically know every service your business has authorised to send as your domain.

A typical SME might use Microsoft 365 for day-to-day mail, a website contact form, an accounting platform, a CRM, an email marketing tool and a support system. Each one may need to be included in your email-authentication setup.

Imagine an engineering firm in Bury that updates its SPF record for Microsoft 365 but forgets its quotation platform. Messages from the team may still arrive, but some customer systems could mark genuine quotes as suspicious. The opposite problem is more serious: an old or overly broad configuration can make it easier for attackers to impersonate the domain.

A simple review plan for this week

  1. List every service that sends email for your domain. Include your main cloud email, website, CRM, newsletters, invoicing, booking and support tools. Ask your IT provider if you are unsure.
  2. Check that SPF is present and tidy. There should be one authoritative SPF record, and it should include only services you still use. Do not add a new sender just because a vendor asks; verify it first.
  3. Confirm DKIM is enabled. Check each approved sending service, not just Microsoft 365 or Google Workspace. DKIM settings can change when domains or platforms are migrated.
  4. Review DMARC reporting and policy. If your setup is new, monitoring is a sensible starting point. Tighten the policy only after you have identified legitimate senders, otherwise genuine messages may be blocked.
  5. Test and document the result. Send test messages from each approved service, check how they are received externally and record who owns the domain settings. A message arriving in your own inbox does not prove that spoofing protection is configured correctly.

Make this a small documented change rather than a one-off technical task. Revisit it when you add a new supplier, change website platforms or move email providers.

One layer of a wider email-security plan

SPF, DKIM and DMARC reduce the chance of criminals successfully pretending to be your domain. They do not protect a mailbox that has genuinely been compromised, stop lookalike domains, or make a malicious link safe. Keep using MFA, sensible payment-verification procedures and staff awareness alongside them.

The most useful next step is to ask whoever manages your domain or IT these three questions:

  • Which services are currently allowed to send as our domain?
  • Is DKIM active for all of them?
  • Are we monitoring DMARC results, and is our policy strong enough?

For many small businesses, the review takes less time than dealing with one convincing fake email. When your email identity is checked, documented and managed the right way, your team has a stronger foundation for working safely every day.

If you would like a second pair of eyes, Managed IT Support Limited can help review your domain records, email senders and wider Microsoft 365 or Google Workspace setup.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation