Right Now, A Stranger Can Email Your Customers As You
No hacking. No stolen password. No malware. A scammer can sit at a laptop in another country and send an email that says it’s from [email protected], and your customer’s inbox will show your real name and your real address. They can ask for a payment, a password reset, or a copy of a contract. And it lands looking completely legit.
This isn’t a hole in your network. It’s a quirk in how email was built back in the 1980s, when nobody thought to ask the sender to prove who they were. Sending email is like dropping a letter in the mailbox. You can write any return address you want on the envelope, and the post office still delivers it.
The good news? There are three settings that slam that door shut. They’re free, they live in your domain settings, and most small businesses I look at have zero of them turned on. Let’s fix that.
The Two Problems You’re Trying to Solve
This one configuration fixes two headaches at the same time, which is rare in IT.
- Spoofing. Crooks impersonate your domain to scam your clients, your vendors, and your own staff. Your reputation takes the hit even though your systems were never touched.
- Deliverability. Your real emails get dumped in spam folders. If you’ve ever sent an invoice or a quote and heard “I never got that,” weak email settings are usually why.
Gmail and Microsoft started cracking down on this in 2024. If your domain doesn’t prove itself, your mail gets throttled, filtered, or bounced. So setting this up isn’t just security. It’s whether your business email actually arrives.
Meet the Three Records That Protect Your Domain
These have ugly acronyms, but the ideas behind them are simple. Think of them as a bouncer, a wax seal, and a rulebook.
SPF: The Guest List
SPF (Sender Policy Framework) is a list of who’s allowed to send email using your domain. Maybe that’s Google Workspace, your Microsoft 365 tenant, your accounting software, and your email marketing tool. SPF publishes that list publicly so receiving servers can check it. If an email claims to be from your domain but comes from a server that isn’t on the list, that’s a red flag.
The catch: a lot of businesses set SPF up years ago, added three new tools since, and never updated it. Now half their real mail fails the check. SPF needs a quick audit any time you add a new service that sends mail on your behalf.
DKIM: The Wax Seal
DKIM (DomainKeys Identified Mail) stamps every outgoing message with a cryptographic signature, like a tamper-proof wax seal on an envelope. The receiving server checks the seal against a key published on your domain. If the seal matches, two things are proven: the mail really came from your domain, and nobody altered it in transit. If someone tampers with the message or fakes it, the seal breaks.
DMARC: The Rulebook
Here’s where it all comes together. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells the world what to do when an email fails the SPF and DKIM checks. You get to pick the rule:
- None: watch and report, but deliver anyway. A safe starting point.
- Quarantine: send failing mail to the spam folder.
- Reject: refuse it outright so it never reaches the inbox.
DMARC also emails you reports showing exactly who’s sending mail using your domain. The first time a client sees one of these reports, the reaction is usually the same: “Wait, who is sending hundreds of emails as us from Russia?” Now you can see it, and now you can stop it.
How to Roll This Out Without Breaking Your Email
Big warning here. Do not flip straight to reject on day one. I’ve watched businesses do that and accidentally block their own newsletters, their booking confirmations, and their CRM. Go in order and give it time.
- Step 1. Make a list of every service that sends email as your business. Email host, marketing platform, invoicing tool, support desk, scheduling app. All of it.
- Step 2. Set up SPF with every one of those services included, and turn on DKIM in your email host (Google Workspace and Microsoft 365 both have a toggle for it).
- Step 3. Publish DMARC set to none. This breaks nothing. It just starts collecting reports.
- Step 4. Read those reports for a few weeks. Fix anything legit that’s failing.
- Step 5. Move to quarantine, watch again, then finally reject. Now spoofed mail in your name is dead on arrival.
What This Actually Means for You
Once this is locked in, a scammer can’t send email pretending to be your domain to anyone running a modern mail system. Your invoices stop landing in spam. Your domain reputation goes up. And you get a monthly report card showing who’s using your name to send mail.
This is one of those projects that’s cheap, high impact, and almost always neglected because it lives in DNS settings nobody likes to touch. One typo in a DNS record can knock your whole company’s email offline, so it’s worth getting a second set of eyes on it.
Want to know if your domain is already protected or wide open? We’ll run a free check on your SPF, DKIM, and DMARC setup and tell you straight what’s exposed. YourTech, serving Delray Beach to West Palm Beach. Securing systems, supporting people.