SPF, DKIM, and DMARC: The Email Security Trio Every Domain Needs
Why your outbound mail lands in spam, how spoofing happens, and a step-by-step guide to configuring authentication without breaking legitimate senders.
If families, donors, or referral partners say your emails go to spam, or worse, they've received fake emails pretending to be your executive director, the fix usually lives in DNS, not in your mail client settings.
SPF, DKIM, and DMARC are the three standards that prove your mail is legitimate and tell receiving servers what to do with impersonation attempts.
What each one does
| Standard | Purpose |
|---|---|
| SPF | Lists which servers may send mail for your domain |
| DKIM | Cryptographic signature proving message wasn't tampered with |
| DMARC | Policy telling receivers how to handle failures + reporting |
You need all three working together. SPF alone is insufficient; DMARC without SPF/DKIM is meaningless.
Common failure modes
- Marketing platform (Mailchimp, HubSpot) not included in SPF
- M365/Google configured but DMARC never published
- DMARC set to
p=rejectbefore testing, legitimate mail blocked - Third-party CRM sending as
@yourdomain.comwithout alignment
Rollout order we recommend
Week 1: Audit every system that sends as your domain (M365, Google, CRM, ticketing, newsletter)
Week 2: Publish SPF including all senders; enable DKIM in M365/Google admin
Week 3: Publish DMARC at p=none with reporting address, collect data
Week 4–6: Review aggregate reports; fix failing sources
Week 7+: Tighten to p=quarantine then p=reject when confident
Why this matters beyond spam
- Cyber insurance increasingly asks about DMARC
- Phishing against your staff often uses spoofed internal domains
- Brand trust, families in crisis won't call back if email feels sketchy
MSP responsibility
If your IT partner manages DNS, they should own this project end-to-end, not hand you a Help article.
Precipice configures email authentication during M365 onboarding and remediation projects. Get in touch.