Insights · Standard · Published 2026-09-15

How to stop email forged in your business's name, in plain English

Three DNS records, SPF, DKIM, and DMARC, tell the world's mail servers which mail is really yours and what to do with the rest.

Anyone can send an email that says it is from you. Email was built without a way to check. Three short records in your domain's DNS fix that: SPF lists who may send for you, DKIM signs each message, and DMARC tells receiving servers to reject mail that fails.

Why mail in your name can be forged

Picture the owner of a Kapaʻa surf shop at the counter. A customer forwards an invoice that came "from" the shop, with new bank details. The owner never sent it. Nothing was hacked. The sender simply typed the shop's address into the From line, the way anyone can write any return address on an envelope.

The From line is a claim, not a proof, unless your domain publishes rules that let servers check it. SPF, DKIM, and DMARC are the rules.

The three, one sentence each

Google's own wording: DMARC "tells receiving email servers what action to take on messages sent from your domain that don't pass SPF or DKIM authentication." The dmarc.org overview says DMARC "builds upon" DKIM and SPF. Without the first two, the third has nothing to enforce.

The four DNS records

DNS is the public phone book for your domain. Four entries matter for mail.

A domain with SPF and DKIM but no DMARC record is telling the world "check my mail, then do whatever you like with the failures."

Which DMARC policy to choose

Google documents three choices and a staged rollout: "When you start using DMARC, we recommend setting the policy option (p) to none. As you learn how messages from your domain are authenticated by receiving servers, update your policy. Over time, change the receiver policy to quarantine (or reject)."

Move too fast and your own invoices land in spam. Never move and the forger keeps a free pass.

What Google and Yahoo now require

In 2024 Google and Yahoo stopped asking and started enforcing.

Google's Email sender guidelines took effect on February 1, 2024. All senders must set up SPF or DKIM, send over a TLS connection, and keep spam rates in Postmaster Tools below 0.3 percent. Senders of 5,000 or more messages a day to Gmail addresses must set up SPF and DKIM, publish a DMARC policy (p=none is acceptable), align the From domain with SPF or DKIM, and support one-click unsubscribe on marketing mail. Google recommends staying below 0.10 percent and never reaching 0.30 percent.

Yahoo's sender hub says enforcement began in February 2024 and rolled out gradually. All senders must implement SPF or DKIM at a minimum and keep spam rates below 0.3 percent. Bulk senders must implement SPF and DKIM and publish a DMARC policy with at least p=none. Yahoo does not publish a volume threshold for "bulk." One-click unsubscribe enforcement began in June 2024, applies to marketing messages only, and unsubscribes must be honored within two days.

A Kauaʻi restaurant with a big newsletter list can cross Google's line on an ordinary day. Under the line you are exempt from the rule, not from forgery.

Check yours in ten seconds

You do not need to read DNS to know where you stand. The free ten-second reading at hawaiiintelligence.com/reading pulls your domain's public records and shows whether SPF, DKIM, and DMARC are present and whether DMARC is enforcing.

If the reading shows no DMARC record or p=none, mail can be sent in your name and delivered. Anyone who has your email address has everything they need.

Ask whoever manages your domain to add the missing records. For how Hawaiʻi businesses score as a group, see the Hawaiʻi Business Email Security Report.

The payment rule for staff

Records protect your name in other people's inboxes. They do not stop a lookalike domain landing in yours. So one rule, posted where staff can see it:

Any request to change bank details, pay a new vendor, or move a payment gets confirmed by phone, at a number we already had on file, before anyone acts. No exceptions for the owner, no exceptions for urgency.

The fake invoice in the surf shop story fails this rule in one phone call. Every other defense is technical. This one is a habit.

Questions owners ask

We only send a few dozen emails a day. Does this apply to us? Yes. Google's bulk rules start at 5,000 messages a day, but forgery does not check your volume. A small domain with no DMARC is easier to impersonate than a large one with p=reject. The standard we hold clients to is all three records, with DMARC enforcing.

Will setting DMARC to reject block my own email? It can, if a real sender is missing from your SPF record or is not signing with DKIM. That is why Google recommends starting at p=none and reading the reports first. Once every legitimate service passes, move to quarantine, then reject.

We use a newsletter tool and a booking system. Do they need setup too? Yes. Each service that sends with your address in the From line needs to be in your SPF record or signing with your DKIM key, or DMARC treats its mail as a failure. Ask each service for its setup page with the exact values to add.

Who actually adds these records? Whoever controls your domain's DNS: usually your web host, your registrar, or the person who built your website. It is a text entry, not a code change. The Google pages below show the exact values.

Sources

Information, not legal, tax, insurance, or financial advice.

Read your own business in ten seconds, free, from public records: hawaiiintelligence.com/reading. Information, not legal, tax, insurance, or financial advice.
Forward this to an ownerEmail it
The Hawaiʻi Business Brief

What every Hawaiʻi business owner needs to know this week. Free, every Tuesday.

Rules and deadlines, recovery programs, scams in circulation, and the Standard. No selling.