2 min read

How DNS, SPF, and DKIM Protect your Domain from Email-Based Threats

How DNS, SPF, and DKIM Protect your Domain from Email-Based Threats

Email authentication standards have moved from “nice to have” to “mandatory.” Microsoft, Google, and Yahoo now require SPF, DKIM, and DMARC for bulk senders, and enforcement is tightening. 

Misconfigurations no longer just hurt deliverability. They can lead to message rejection and increase exposure to domain spoofing.

 

Email Authentication Isn’t Optional: What IT Teams Must Know About SPF, DKIM, and DNS

 

In Part 2 of our podcast series, we go beyond the basics and talk through why DNS is the control plane for trust and how SPF/DKIM missteps can leave organizations exposed. 

That makes DNS, SPF, and DKIM non-negotiable for IT leaders responsible for protecting brand trust and ensuring reliable communication. 

 

Listen to the episode

 

 

 

 

DNS: The Control Plane 

 

Every authentication control for email lives in DNS. If your records aren’t accurate, secure, and maintained, your organization loses control over who can send in your name. 

Priorities for IT leaders: 

  • Maintain direct control of your registrar and DNS provider accounts. 
  • Implement DNSSEC to prevent record tampering. 
  • Standardize on a provider with strong uptime SLAs (Cloudflare, AWS Route 53, etc.). 

 

SPF: Sender Authorization 

 

SPF defines which mail servers are authorized to send on behalf of your domain. It’s simple in principle, but many organizations break it by stacking multiple SPF records or exceeding the 10-lookup limit. 

Best practices: 

  • Consolidate into one SPF record per domain. 
  • Audit and update regularly when new services are added (marketing, billing, HR platforms). 
  • Validate syntax with MXToolbox before publishing changes. 

 


 

These issues are more common than most teams expect, especially as new services get added over time. Even small mistakes in SPF, DKIM, or DNS records can lead to authentication failures or unexpected delivery problems. 

Run a quick scan below to validate your domain's configuration. 

 

If your results highlight errors or inconsistencies, those should be addressed before building more advanced controls like DMARC enforcement or transport-layer protections. 

 

 

 


 

DKIM: Message Integrity 

 

DKIM signs outbound email so receiving servers can verify it wasn’t altered in transit. Microsoft 365 supports DKIM natively, but most tenants leave the default setup incomplete. 

Key actions: 

  • Enable DKIM signing for all custom domains. 
  • Publish CNAME records from the Microsoft 365 Security & Compliance Center. 
  • Rotate keys periodically and align DKIM with each sending service. 

 

Get Strategic with Email Authentication to Strengthen Domain Trust with Sourcepass MCOE

 

SPF and DKIM don’t stop all phishing. But without them, your domain can be freely impersonated, and your legitimate mail may not reach the inbox. Together with DNS, they form the foundation for DMARC, which adds reporting and enforcement. That’s where visibility and control really begin.

Part 3 of this series covers how to implement DMARC for full protection.

 

 

Get in touch with our experts

 

Best Microsoft Copilot Frontier Features to Test First

4 min read

Best Microsoft Copilot Frontier Features to Test First

The Copilot that frustrated your early testers is not the Copilot Microsoft is shipping through Frontier. Excel handles hundreds of thousands of...

Read the full article
Why Device Code Flow Phishing Bypasses MFA in Microsoft 365

5 min read

Why Device Code Flow Phishing Bypasses MFA in Microsoft 365

The most dangerous Microsoft 365 attack right now is the one that does not look like an attack.

Read the full article
Why FIDO2 and Passkeys are the New MFA Standard for Microsoft 365

5 min read

Why FIDO2 and Passkeys are the New MFA Standard for Microsoft 365

Attackers no longer need a password to take over a Microsoft 365 account. They just need a session token, and they are getting it after users...

Read the full article
Securing Email in Transit with MTA-STS, TLS-RPT, and DANE

1 min read

Securing Email in Transit with MTA-STS, TLS-RPT, and DANE 

Attackers don’t just target users anymore. They exploit the gaps in the infrastructure that moves email across the internet. Encryption in transit...

Read the full article
Email Security Tools That Actually Make a Difference in Microsoft 365

1 min read

Email Security Tools That Actually Make a Difference in Microsoft 365

Email remains one of the most common ways attackers gain access to organizations. DNS, SPF, DKIM, and DMARC serve as identity checks that verify...

Read the full article
Preventing Token Theft and Phishing in Microsoft 365

1 min read

Preventing Token Theft and Phishing in Microsoft 365

Token theft and phishing attacks in Microsoft 365 are increasing fast. Over half of surveyed organizations reported a breach in the past year.

Read the full article