Patrick Jensen-PC Good Guys OwnerDMARC: One DNS Record That Can Help Stop Criminals From Impersonating Your Business

Your business email address may be easier to impersonate than you think.

Email spoofing is one of those cybersecurity problems many small businesses don’t think about until a customer, employee, or vendor receives a fraudulent email that appears to have come directly from their company.

The frightening part? A criminal doesn’t necessarily need to hack your email account to impersonate your domain.

They may simply attempt to send an email that looks like it came from you.

That’s where DMARC comes in.

At PC Good Guys, I work with small and midsized businesses throughout Minnesota to improve their IT infrastructure and cybersecurity. One important—and frequently overlooked—part of protecting a company’s online identity is properly configuring its email authentication DNS records.

What Is Email Spoofing?

Email spoofing occurs when someone manipulates an email so it appears to originate from another person or organization.

Imagine receiving an email that appears to come from:

accounting@yourcompany.com

The company name looks correct. The domain looks correct. The employee’s name may even be correct.

But the message wasn’t actually sent by your company.

Microsoft describes spoofing as messages that appear to originate from somewhere other than their actual source and notes that the technique is commonly used in phishing campaigns.

A fraudulent message might tell an employee to:

  • Pay an attached invoice.
  • Change a vendor’s bank information.
  • Purchase gift cards.
  • Reset a password.
  • Open a malicious attachment.
  • Sign into a fake Microsoft 365 page.
  • Send confidential company information.

Because the visible From address appears legitimate, an employee or customer may be much more likely to trust it.

DMARC Helps Protect Your Domain

DMARC stands for Domain-based Message Authentication, Reporting, and Conformance.

DMARC is published as a DNS record for your domain and works alongside two other important email authentication technologies:

SPF — Sender Policy Framework

SPF identifies which email servers and services are authorized to send email on behalf of your domain.

DKIM — DomainKeys Identified Mail

DKIM uses a cryptographic signature that allows receiving email systems to verify that an email was legitimately signed by an authorized domain and hasn’t been improperly altered.

DMARC—Domain-based Message Authentication, Reporting, and Conformance

DMARC ties email authentication together by checking whether the authenticated domain aligns with the domain users actually see in the email’s From: address. It can also tell receiving systems what should happen when a message fails authentication.

You can learn more about the standard directly from DMARC.org.

What Happens When DMARC Isn’t Configured?

Without an effective DMARC policy, your domain has less ability to tell receiving email systems how they should handle messages that pretend to come from your organization but fail authentication.

That doesn’t mean DMARC magically stops every phishing attack. Attackers can still register look-alike domains, compromise legitimate accounts, or use other social-engineering techniques.

But DMARC addresses a very specific and important problem:

Someone attempting to directly impersonate your email domain.

This can be particularly important for businesses that regularly communicate with customers about invoices, payments, contracts, payroll, financial information, or confidential documents.

Your domain is part of your company’s identity. Protecting it should be treated much like protecting your company name, bank account, or physical property.

DMARC Policies: None, Quarantine, and Reject

A DMARC DNS record includes a policy that tells participating receiving email systems how you want authentication failures handled.

There are three primary policy levels:

p=none

This is primarily a monitoring policy. DMARC reports can be collected, but failing messages aren’t specifically requested to be quarantined or rejected by the DMARC policy.

p=quarantine

Messages that fail DMARC are requested to be treated suspiciously—often resulting in placement in a spam or quarantine folder.

p=reject

Messages that fail DMARC are requested to be rejected.

It might seem logical to immediately configure every business for p=reject, but that can be a mistake.

Don’t Just Add a DMARC Record and Hope for the Best

Modern businesses frequently have several legitimate systems sending email using their domain.

That might include:

Microsoft 365, Google Workspace, accounting applications, CRM systems, website contact forms, ticketing platforms, marketing services, payroll applications, scanners, multifunction printers, and other cloud services.

Every legitimate sender needs to be considered.

Microsoft specifically notes that third-party services can fail DMARC when authentication isn’t properly aligned with the domain appearing in the From address.

That’s why a good DMARC deployment often begins with monitoring.

We can review which systems are legitimately sending email for the organization, verify SPF and DKIM, examine DMARC reports, correct authentication problems, and then move toward a stronger enforcement policy.

Turning on an aggressive reject policy without understanding your email environment could potentially cause legitimate business email to be rejected.

DMARC Can Help Your Email Deliverability, Too

Email authentication isn’t only about stopping criminals.

It’s increasingly important for successfully delivering legitimate email.

Google’s current Gmail sender guidelines recommend configuring SPF, DKIM, and DMARC. Google says authenticated messages help protect organizations from impersonation and are less likely to be rejected or marked as spam.

For organizations sending more than 5,000 messages per day to personal Gmail accounts, Google requires SPF, DKIM, and DMARC, along with other sender requirements.

Even if your small business sends nowhere near 5,000 emails per day, properly authenticating your domain is still an excellent practice.

Your legitimate email should look legitimate to the receiving server.

“We Use Microsoft 365, So Aren’t We Already Protected?”

Not necessarily.

Using Microsoft 365 or another major email provider doesn’t automatically mean every DNS authentication record for your custom domain is configured correctly.

Your Microsoft 365 tenant, DNS provider, and any third-party systems that send email on your behalf all need to work together.

Microsoft identifies SPF, DKIM, and DMARC as important components of email authentication and anti-spoofing protection.

A business can have perfectly functioning Microsoft 365 mailboxes while still having an incomplete SPF record, DKIM that hasn’t been enabled, no DMARC policy, or third-party senders that aren’t properly authenticated.

Those are exactly the types of configuration details worth reviewing.

Protect More Than Your Inbox—Protect Your Reputation

Consider what happens when a customer receives a fraudulent invoice that appears to come from your company.

Even if your systems weren’t technically compromised, the customer may associate the scam with your business.

That’s why email authentication isn’t merely an IT issue.

It’s a business reputation issue.

DMARC, SPF, and DKIM can help protect your employees, customers, vendors, and business relationships while making it more difficult for criminals to successfully impersonate your domain.

When Was the Last Time Your Business Email Security Was Reviewed?

If the answer is “I don’t know,” that’s probably a good reason to have it checked.

PC Good Guys can review your business email and DNS configuration, including your SPF, DKIM, and DMARC records; identify legitimate email-sending services; troubleshoot authentication issues; and help establish an appropriate DMARC deployment strategy.

I can also look beyond email authentication and help identify other weaknesses in your company’s technology and cybersecurity environment.

PC Good Guys provides local Business IT Services and Managed IT Services for small and midsized businesses throughout Bloomington, Minneapolis, St. Paul, and surrounding Twin Cities communities.

Don’t wait until a customer calls asking why “you” sent them a suspicious invoice.

Protect your domain before someone else tries to use it.

Need Your DMARC, SPF & DKIM Records Checked?

If you’re unsure whether your company’s domain is properly protected against email spoofing, contact PC Good Guys.

I’ll review your configuration, identify potential problems, and help make sure your legitimate email systems are properly authenticated.

Contact PC Good Guys today and let’s make it considerably harder for scammers to pretend they’re you.

PC Good Guys — Business IT Sales & Support
Serving Bloomington and businesses throughout the Twin Cities.