How Email Authentication (SPF, DKIM, DMARC) Stops Spoofing
SPF, DKIM and DMARC let receiving mail servers spot emails that fake your domain. A plain-English guide to what each one does, what they cannot stop, and where to start.

Email was designed without a way to prove who sent a message, which is why anyone can type your company's name and address into the "From" line. Three standards, SPF, DKIM and DMARC, let the receiving mail server check whether an email claiming to be from your domain really is.
The three standards in plain English
| Standard | What it does | Simple analogy |
|---|---|---|
| SPF | Publishes a list of servers allowed to send email for your domain. | A guest list at the door. |
| DKIM | Adds a digital signature that proves the message came from your domain and was not altered. | A wax seal on a letter. |
| DMARC | Tells receivers what to do when SPF or DKIM fails, and sends you reports. | Instructions to security: turn them away, and tell me who tried. |
What they stop, and what they do not
With a strict DMARC policy, emails that pretend to come from exactly yourcompany.com get rejected or sent to spam. That protects your customers, suppliers and staff from the simplest impersonation.
They do not stop:
- Lookalike domains such as
yourcompany-invoices[.]com. - Display name tricks, where only the name is faked. See checking the sender address.
- Emails from genuinely compromised accounts. See vendor email compromise.
Where to start
- List every service that sends email as your domain: your mail provider, newsletter tool, invoicing system, website forms.
- Set up SPF and DKIM for each, using your providers' instructions.
- Publish a DMARC record in monitoring mode and read the reports.
- Once legitimate mail passes, move to quarantine and then reject.
If someone is already phishing with your brand, see responding to brand impersonation.
For the full picture, see how to protect yourself from phishing.
Frequently asked questions
Do SPF, DKIM and DMARC stop all phishing?
No. They stop exact spoofing of your domain. They do not stop lookalike domains, display name tricks or emails from genuinely hacked accounts.
Is this only for big companies?
No. Any organization that sends email from its own domain, including small businesses, clubs and charities, should set them up.
What DMARC policy should we start with?
Many organizations start with a monitoring policy to see reports, fix legitimate senders, then move to quarantine and reject.
Sources
- Email security and anti-spoofing, UK National Cyber Security Centre
- Overview, DMARC.org
- Phishing attacks: defending your organisation, UK National Cyber Security Centre


