Scammers can send an email that appears to use your business name or domain. A fake message may ask a customer to pay a different bank account or tell a staff member to open a harmful file.
SPF, DKIM and DMARC are settings that help receiving mail systems check messages claiming to come from your domain. Together, they make it harder for someone to send mail that uses your exact domain without permission. They can also improve delivery of legitimate email.
They do not prove that every message is honest, and they do not stop every email scam.
Start with your domain name
Your domain is the part after the @ symbol in an email address, such as yourbusiness.com.au.
Your business may send mail through Microsoft 365 or Google Workspace. Other services, such as accounting, booking and marketing platforms, may also send messages using the same domain.
The domain settings need to account for each approved sender without giving unnecessary services permission.
What SPF does
SPF stands for Sender Policy Framework. It publishes a list of systems allowed to send mail for a domain.
When a message arrives, the receiving system can compare the sending service with that list. This helps identify mail sent through an unexpected system.
SPF can fail when old services remain listed, new services are missing or the record grows beyond its technical limits. Forwarded mail can also complicate the check. SPF needs ongoing maintenance, not a one-time copy and paste.
What DKIM does
DKIM stands for DomainKeys Identified Mail. An approved mail service adds a digital signature to a message. The receiving system checks that signature against information published by the domain owner.
A valid signature helps show that the approved service signed the message and that signed parts of it were not changed in transit.
DKIM normally works in the background. It must be enabled for each relevant sending service, and its signing information must be maintained when services change.
What DMARC does
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It connects the visible From address with SPF or DKIM and tells receiving systems how the domain owner wants failed messages handled.
A DMARC policy can ask receiving systems to:
- monitor failures without requesting that mail be blocked
- place failed mail in spam or quarantine
- reject failed mail
DMARC can also send reports about services using the domain. Those reports help identify legitimate senders that have not been configured correctly and attempts that the business does not recognise.
Why the settings work together
SPF checks the sending system. DKIM checks a digital signature. DMARC checks that one of those results properly matches the domain shown to the reader, then applies the published policy.
That matching step matters. SPF alone does not stop every message from displaying your domain in the From line.
A staged setup is usually safer. Start by identifying every legitimate sender, correct SPF and DKIM, review DMARC reports, then move to a stricter policy when the results support it. Moving straight to rejection without checking can block genuine invoices, booking messages or website forms.
What these settings do not stop
A scammer can register a similar-looking domain, compromise a real mailbox or use a supplier's account. SPF, DKIM and DMARC also do not judge whether a genuine account is sending a dishonest request.
Businesses still need strong account protection, staff training and a separate check for payment or bank detail changes.
Signs the setup needs review
Review the domain settings when:
- legitimate messages start going to junk
- customers report fake mail using the business domain
- a new email, invoicing, booking or marketing service is introduced
- the website or IT provider changes
- nobody can say which services are authorised to send
Document every approved sender and who owns it. Remove old entries when a service is retired.
If you do not know which services send mail for your domain, contact JCPIT for an email domain check. We will map the approved senders, identify gaps and plan any stricter policy without cutting off genuine invoices, bookings or website messages.