SPF, DKIM and DMARC without the mystique
Three records. One policy you tighten over time. The cheapest email-forgery control you are not done with.
ITSIGN Administrator · September 17, 2025 · 2 min read
SPF says who may send. DKIM signs the message. DMARC says what to do when they disagree, and where to send the report.
Start in monitor. Watch the reports. Move to quarantine, then reject, when you know every legitimate sender — including the marketing tool nobody told IT about.
We implement this under cloud and Microsoft 365.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
