Insights · Standard · Published 2026-09-15
How to stop email forged in your business's name, in plain English
Three DNS records, SPF, DKIM, and DMARC, tell the world's mail servers which mail is really yours and what to do with the rest.
Anyone can send an email that says it is from you. Email was built without a way to check. Three short records in your domain's DNS fix that: SPF lists who may send for you, DKIM signs each message, and DMARC tells receiving servers to reject mail that fails.
Why mail in your name can be forged
Picture the owner of a Kapaʻa surf shop at the counter. A customer forwards an invoice that came "from" the shop, with new bank details. The owner never sent it. Nothing was hacked. The sender simply typed the shop's address into the From line, the way anyone can write any return address on an envelope.
The From line is a claim, not a proof, unless your domain publishes rules that let servers check it. SPF, DKIM, and DMARC are the rules.
The three, one sentence each
- SPF is a public list of the servers allowed to send mail for your domain, so a receiving server can check whether a message came from one of them.
- DKIM puts a digital signature on every message you send, which the receiving server verifies against a public key you publish.
- DMARC tells receiving servers what to do with a message that fails SPF or DKIM (deliver, spam folder, or reject) and sends you a report on what it saw.
Google's own wording: DMARC "tells receiving email servers what action to take on messages sent from your domain that don't pass SPF or DKIM authentication." The dmarc.org overview says DMARC "builds upon" DKIM and SPF. Without the first two, the third has nothing to enforce.
The four DNS records
DNS is the public phone book for your domain. Four entries matter for mail.
- MX record. Where your incoming mail is delivered. Your mail provider set this when you signed up.
- SPF record. A TXT record on your domain. Google's published example for a domain that sends only through Workspace is v=spf1 include:_spf.google.com ~all. Every service that sends in your name (booking system, invoicing tool, newsletter service) needs its own include. Google notes a record can hold up to 10 include tags.
- DKIM record. A TXT record at a name like google._domainkey under your domain, holding a public key. Google recommends a 2048-bit key where your DNS provider supports it.
- DMARC record. A TXT record at _dmarc.yourdomain.com. Google's example begins v=DMARC1; p=reject; rua=mailto:... The p tag is the policy. The rua tag is where reports go.
A domain with SPF and DKIM but no DMARC record is telling the world "check my mail, then do whatever you like with the failures."
Which DMARC policy to choose
Google documents three choices and a staged rollout: "When you start using DMARC, we recommend setting the policy option (p) to none. As you learn how messages from your domain are authenticated by receiving servers, update your policy. Over time, change the receiver policy to quarantine (or reject)."
- p=none delivers everything and sends you a daily report. It protects no one yet, but it shows every service sending in your name.
- p=quarantine sends failures to the recipient's spam folder.
- p=reject refuses them. The receiving server usually sends a bounce.
Move too fast and your own invoices land in spam. Never move and the forger keeps a free pass.
What Google and Yahoo now require
In 2024 Google and Yahoo stopped asking and started enforcing.
Google's Email sender guidelines took effect on February 1, 2024. All senders must set up SPF or DKIM, send over a TLS connection, and keep spam rates in Postmaster Tools below 0.3 percent. Senders of 5,000 or more messages a day to Gmail addresses must set up SPF and DKIM, publish a DMARC policy (p=none is acceptable), align the From domain with SPF or DKIM, and support one-click unsubscribe on marketing mail. Google recommends staying below 0.10 percent and never reaching 0.30 percent.
Yahoo's sender hub says enforcement began in February 2024 and rolled out gradually. All senders must implement SPF or DKIM at a minimum and keep spam rates below 0.3 percent. Bulk senders must implement SPF and DKIM and publish a DMARC policy with at least p=none. Yahoo does not publish a volume threshold for "bulk." One-click unsubscribe enforcement began in June 2024, applies to marketing messages only, and unsubscribes must be honored within two days.
A Kauaʻi restaurant with a big newsletter list can cross Google's line on an ordinary day. Under the line you are exempt from the rule, not from forgery.
Check yours in ten seconds
You do not need to read DNS to know where you stand. The free ten-second reading at hawaiiintelligence.com/reading pulls your domain's public records and shows whether SPF, DKIM, and DMARC are present and whether DMARC is enforcing.
If the reading shows no DMARC record or p=none, mail can be sent in your name and delivered. Anyone who has your email address has everything they need.
Ask whoever manages your domain to add the missing records. For how Hawaiʻi businesses score as a group, see the Hawaiʻi Business Email Security Report.
The payment rule for staff
Records protect your name in other people's inboxes. They do not stop a lookalike domain landing in yours. So one rule, posted where staff can see it:
Any request to change bank details, pay a new vendor, or move a payment gets confirmed by phone, at a number we already had on file, before anyone acts. No exceptions for the owner, no exceptions for urgency.
The fake invoice in the surf shop story fails this rule in one phone call. Every other defense is technical. This one is a habit.
Questions owners ask
We only send a few dozen emails a day. Does this apply to us? Yes. Google's bulk rules start at 5,000 messages a day, but forgery does not check your volume. A small domain with no DMARC is easier to impersonate than a large one with p=reject. The standard we hold clients to is all three records, with DMARC enforcing.
Will setting DMARC to reject block my own email? It can, if a real sender is missing from your SPF record or is not signing with DKIM. That is why Google recommends starting at p=none and reading the reports first. Once every legitimate service passes, move to quarantine, then reject.
We use a newsletter tool and a booking system. Do they need setup too? Yes. Each service that sends with your address in the From line needs to be in your SPF record or signing with your DKIM key, or DMARC treats its mail as a failure. Ask each service for its setup page with the exact values to add.
Who actually adds these records? Whoever controls your domain's DNS: usually your web host, your registrar, or the person who built your website. It is a text entry, not a code change. The Google pages below show the exact values.
Sources
- Google Workspace Admin Help, Email sender guidelines. Supports the February 1, 2024 date, the 5,000 messages per day threshold, SPF or DKIM for all senders, SPF plus DKIM plus DMARC for bulk senders, p=none minimum, alignment, one-click unsubscribe, and the 0.10 and 0.30 percent spam rates. support.google.com/a/answer/81126. Fetched 2026-09-14.
- Google Workspace Admin Help, Set up DMARC. Supports the DMARC definition, the none, quarantine, and reject policies, the _dmarc TXT location, the example record, and the rollout advice. knowledge.workspace.google.com/admin/security/set-up-dmarc. Fetched 2026-09-14.
- Google Workspace Admin Help, Set up SPF. Supports the SPF definition, the example record, and the 10 include tag limit. knowledge.workspace.google.com/admin/security/set-up-spf. Fetched 2026-09-14.
- Google Workspace Admin Help, Set up DKIM. Supports the DKIM signature definition, the _domainkey record location, and the 2048-bit key recommendation. knowledge.workspace.google.com/admin/security/set-up-dkim. Fetched 2026-09-14.
- dmarc.org, Overview. Supports that DMARC builds on SPF and DKIM, the three policy levels, and reporting. dmarc.org/overview. Fetched 2026-09-14.
- Yahoo Sender Hub, sender requirements. Supports the February 2024 enforcement start, SPF or DKIM minimum, DMARC with at least p=none for bulk senders, the 0.3 percent spam rate, and the two-day unsubscribe rule. senders.yahooinc.com/best-practices. Fetched 2026-09-14.
- Yahoo Sender Hub, FAQs. Supports that Yahoo publishes no bulk volume threshold, the June 2024 start of one-click unsubscribe enforcement, and its limit to marketing messages. senders.yahooinc.com/faqs. Fetched 2026-09-14.
Information, not legal, tax, insurance, or financial advice.
Read your own business in ten seconds, free, from public records:
hawaiiintelligence.com/reading. Information, not legal, tax, insurance, or financial advice.
Forward this to an ownerEmail it