SPF, DKIM and DMARC: stop people spoofing your company email
Updated 10/5/2026 · 5 min read
If your business domain doesn't have SPF, DKIM and DMARC set up, scammers can send emails that look exactly like they came from your address — to your customers, your suppliers, even your own staff. This is how a lot of invoice fraud and phishing starts.
What each one does - **SPF** lists which mail servers are allowed to send email for your domain. - **DKIM** adds a cryptographic signature so receivers can verify the message really came from you and wasn't altered. - **DMARC** ties the two together and tells receiving servers what to do with email that fails — and sends you reports.
Getting it right 1. Publish an **SPF** record listing your real senders (your email provider, any marketing tools). 2. Turn on **DKIM** in your email provider and publish the key it gives you. 3. Add a **DMARC** record, start at `p=none` to watch the reports, then move to `quarantine` and `reject` once legitimate mail passes.
How to check Keepvik's free domain check reads these records for your domain and tells you in plain language what's missing and how serious it is.
Want to check your own PC?
The free Quick Scan looks for everything in this guide in about a minute.
Free Quick Scan