An SPF record lists the mail systems allowed to send on behalf of a domain. Keep the record accurate and avoid creating multiple SPF records. Every legitimate sender, including marketing or ticketing platforms, needs to be considered.
DKIM protects message integrityDKIM adds a cryptographic signature that receiving systems can validate through DNS. It helps show that an authorised service sent the message and that signed content was not changed in transit.
DMARC sets the policyDMARC checks alignment between the visible From address and SPF or DKIM authentication. It also tells receivers how to handle failures and can provide reports that reveal legitimate services, mistakes and attempts to impersonate the domain.
Move toward enforcement carefullyStart by collecting reports and inventorying every approved sender. Correct alignment problems before progressing from monitoring to quarantine or reject. Sudden enforcement without discovery can block legitimate invoices, support messages or newsletters.
Authentication is one layerThese controls reduce domain spoofing but do not stop every deceptive message. Combine them with multifactor authentication, protected mail submission, user awareness and a clear process for reporting suspicious email. Viewertech can review the DNS and mail-server configuration as one coordinated control set.
Talk to ViewertechFor practical guidance tailored to your organisation, contact the Viewertech team.
