IT Pro Expert
Search
IT PRO EXPERT

Email Authentication

Email authentication and spam protection — DMARC, SPF and DKIM. Is your email secured with all the correct deliverability policies?

Email protection

DKIM, DMARC and SPF are the three requirements. Check your business email domain and test your setup with these tools:

DKIM, DMARC and SPF

Ensure email deliverability and security for your business by implementing DKIM, DMARC and SPF in your server configuration. Since April 2024 these policies are a requirement for compliance with companies like Google, Microsoft and Yahoo. This also helps prevent abuse of your business domain and user accounts.

In addition, you can add an email filtering service such as Microsoft Defender for Exchange, Mimecast, FortiMail or Proofpoint for the highest level of protection.

DKIM SPF DMARC email authentication

Why it matters

Email authentication settings ensure that your emails get delivered into inboxes and not spam boxes. They also help protect your domain from being used for outbound spam by scammers or spammers. All email addresses that have their own domain name need to be configured and authenticated for SPF, DKIM and DMARC to ensure validated delivery under the 2024 global compliance requirements.

If you wonder why your emails are frequently going to other people's spam boxes, not being delivered, or being marked as a "risk to view" or carrying warning alerts, then you need to get your email authentication set up correctly. A simple configuration reduces the risk of hackers spoofing your email address and ruining your business reputation, which can be difficult to recover from.

Following the requirements will help reduce and block spam, spoofing, fraud and phishing. Never bulk email from your domain name if you want to ensure deliverability in the future — always use a different domain or subdomain to do this. When enough people in a larger receiving group like Gmail tag your emails as spam, you will continue to have deliverability issues.

If you need to get your domain's email secured, then give IT Pro Expert a call and we will gladly assist you with this process.

What each record does

DKIM, SPF and DMARC allow internet mail services to verify that a sender is authorised to send email from your domain. Together they block third parties from sending emails using your domain name and pretending to be you.

DKIM

DomainKeys Identified Mail sends an encryption key and digital signature, which verifies that emails are not faked or tampered with during the journey from sender to receiver.

SPF

Sender Policy Framework provides the origin data behind an email message, including the sending IP address and the mail server connecting to the client. It lets domain owners configure which email servers are authenticated to send their messages.

DMARC

Domain-based Message Authentication, Reporting and Conformance is the primary enforcement system. DMARC unifies the SPF and DKIM components into a functional solution, and lets you set a permanent pass, quarantine or delete on any unauthenticated email.

Configuring all of these components is a difficult task. It requires complex DNS configuration and testing, and can easily be misconfigured by an inexperienced user, causing email outages or dropped emails.

Setup guide for Microsoft 365 platforms

A guide for IT companies that use Microsoft 365 platforms. Please follow these instructions.

  1. Open both consoles

    Open your DNS configuration website — typically wherever the domain name was purchased — and go to DNS configuration. At the same time, open your 365 admin configuration at admin.microsoft.com for the same domain and log in.

  2. DKIM

    Start from the 365 admin DKIM page and run the diagnostic test, or go straight to the DKIM configuration at security.microsoft.com/dkimv2. Look at the list of DomainKeys Identified Mail (DKIM) domain names and click the line with the domain you are setting up. A right-hand panel appears with the option to enable.

    If DKIM is already enabled on the 365 admin DKIM page side panel, disable it for five minutes and then re-activate it, otherwise it will fail to give you the right settings. There is no need to rotate keys.

    You will get two new DNS records to enter as CNAME entries, using TTL 3600 if asked. First entry — host selector1._domainkey, value selector1-THISISPROVIDEDBYMICROSOFT01e._domainkey.THISISPROVIDEDBYMICROSOFT.onmicrosoft.com. Second entry — host selector2._domainkey, value selector2-THISISPROVIDEDBYMICROSOFT01e._domainkey.THISISPROVIDEDBYMICROSOFT.onmicrosoft.com.

  3. DMARC

    Add the following to your DNS as a TXT record, changing the example email address to one of your own. Host _dmarc, value v=DMARC1; p=reject; pct=100; rua=mailto:email@mydomainname.com; ruf=mailto:email@mydomainname.com; fo=1

    Advanced details on DMARC options: mxtoolbox.com DMARC tags.

  4. SPF

    Insert a new TXT record in the DNS: v=spf1 include:spf.protection.outlook.com -all

    If you have multiple email engines, such as HubSpot, do it like this instead — host @, value v=spf1 include:spf.protection.outlook.com include:1234567.spf01.hubspotemail.net ~all

  5. Check your work

    Run a check using the dmarcian domain checker and make sure all three of DKIM, DMARC and SPF are working.

DMARC SPF DKIM domain checker results
Your results should look like this

Email authentication

Sales lines are open 9:30 to 5:30 and critical support is available 24/7. Contact us for any service not listed on this page.

Get in touch