What is email authentication?
Here's the uncomfortable truth email was built on: by default, anyone can put your company's name on an email — the same way anyone can scribble your address on the back of an envelope. Nothing in the original design stops a stranger from sending a fake invoice that looks like it came from you.
Email authentication fixes that. It's a set of three checks that let the big inbox providers — Gmail, Outlook, Yahoo — confirm a message really came from you, and quietly bin the ones that didn't. The three checks are SPF, DKIM and DMARC, and they work as a team:
- SPF proves the message came from a server you approve.
- DKIM proves the message wasn't tampered with on the way.
- DMARC ties the two together, sets the rule for fakes, and reports who's sending as you.
You need all three. SPF and DKIM each cover one angle; DMARC is the one that actually stops impersonation and lets you see it happening.
SPF The approved-senders list
SPF (Sender Policy Framework) is a public list of the servers allowed to send email for your domain — think of it as the guest list at the door. When a message arrives claiming to be from you, the receiving inbox asks one question: "Was this sent from a server on the list?" If yes, it looks legitimate. If not, it's treated as suspicious.
v=spf1 include:_spf.google.com include:sendgrid.net ~all
The catch: add a new tool — a newsletter platform, an invoicing app, a booking system — and forget to add it to this list, and your real mail starts failing and landing in spam. That's why SPF isn't "set and forget"; it needs watching.
DKIM The tamper-proof seal
DKIM (DomainKeys Identified Mail) adds an invisible, un-forgeable wax seal to every email you send. The receiving inbox checks the seal: if it's intact, the message genuinely came from you and nothing was changed in transit. If the seal is missing or broken, the message can't be trusted.
Because the seal is cryptographic, an impersonator can't fake it — they don't have your private key. DKIM also survives some forwarding that SPF doesn't, which is why you want both.
DMARC The rulebook & your CCTV
DMARC (Domain-based Message Authentication, Reporting & Conformance) is the one that pulls it all together. It does two powerful things:
- Sets the rule. A message must pass SPF or DKIM and the name must match your visible "From" address. Then you decide what happens to anything that fails.
- Turns on the CCTV. DMARC quietly emails you daily reports of everyone sending mail as you — the good and the fake. This is how you finally see impersonation.
You choose how strict the rule is, and you tighten it over time as you gain confidence:
v=DMARC1; p=reject; rua=mailto:reports@yourdomain.co.uk
Gmail & Yahoo now require this
Since February 2024, Gmail and Yahoo require a valid DMARC record for anyone sending email in volume. No DMARC no longer just means "less secure" — it means your legitimate mail is likelier to be filtered to spam or rejected outright. Email authentication has gone from best-practice to mandatory.
How MailSurety does this for you
The records above are only a few lines of DNS — but getting all three right, and keeping them right every time you add a new tool, is exactly where most businesses trip up. One wrong character and your real invoices go to spam; one gap and someone's forging your name without you knowing.
That's the whole job MailSurety does:
- We set up SPF, DKIM and DMARC with you — or check what you already have.
- We read your DMARC reports every day, so you never have to open one.
- We tell you in plain English what's fine and what to fix — "this is your newsletter, that's a fake, block it."
- We guide you safely from watching to blocking, without losing a single real email.
See where your domain stands — free
Instant score of your live SPF, DKIM & DMARC setup. No signup, nothing stored.
Common questions
Do I need all three of SPF, DKIM and DMARC?
Yes. SPF and DKIM are two independent ways to prove a message is really from you; DMARC ties them together, tells inboxes what to do with fakes, and reports who's sending as you. DMARC in particular is what actually stops impersonation and gives you visibility.
What happens if I don't have DMARC?
Anyone can send email that appears to come from your domain, and you'll never see it happening. And since February 2024, Gmail and Yahoo require a valid DMARC record for bulk senders — so without it your legitimate email is likelier to hit spam or be rejected.
Is setting this up complicated?
The records are a few lines of DNS, but getting them right — and keeping them right as you add tools like a CRM or newsletter — is fiddly and easy to break. MailSurety sets all three up and monitors them for you, in plain English.
Does this let anyone read my email?
No. DMARC reports contain only statistics — which servers sent mail as you and whether it passed. Never message content, subjects or attachments. Your real email never passes through MailSurety.