BusinessGoogle WorkspaceSecurity

Improve email security on your domain

Stop criminals sending fake invoices from your domain. How SPF, DKIM and DMARC protect your clients and staff from email impersonation, in plain language.

· Updated · 3 min read

Illustration of a hooded hacker reaching out of one laptop with a fishing rod to hook a folder labelled Personal Data on another

A professional email address on your company domain is the first step in showing that you’re a legitimate business. But is it enough to protect your clients and employees against email fraud?

According to Mimecast’s 2020 Threat Intelligence Report, impersonation attacks increased by nearly two-thirds compared with the previous year’s report. Of the organisations hit by an impersonation attack, 69% experienced a direct loss: lost customers, financial loss, data loss, or a combination of these.

Most notably, 88% of South African respondents experienced a phishing attack in the previous 12 months.

You might be wondering what this has to do with you or your business.

Take a typical accounts department. The people who work there are used to sending and receiving sensitive financial information like customer invoices, bank statements, proofs of payment and supplier invoices.

By impersonating someone from your accounts department, an attacker can send your clients fake invoices, fake banking details and fake requests to log in and reset their passwords on a compromised website.

With proper email security on your domain, much of this risk can be eliminated, because the recipient’s email service can verify that email sent from your domain is legitimate.

Our clients don’t need to understand, or even notice, the technical details of the extra precautions we take to protect their domains. It does help to know a little about how these measures work, if only to see that they’re not magic bullets or obscure technology, but standard good practice. It’s a practice we hope more service providers will adopt for their clients.

We implement three technologies at DNS level: SPF, DKIM and DMARC. DNS is the system that lets the rest of the internet find your website and deliver your email, and it’s usually under the control of your ISP.

What is SPF?

SPF is short for Sender Policy Framework. An SPF record lets other servers know which networks and servers can be trusted to send email on behalf of your domain.

When you send an email, the recipient’s mail server checks the message headers to verify that it came from an approved source. If it fails this check, the email may be treated as suspicious, labelled as spam or blocked outright. Email that passes the SPF check is delivered as legitimate email from a legitimate source.

All you need to activate SPF on your domain is a TXT record in your domain’s DNS configuration.

An SPF record that tells servers to trust email from Google (Gmail) looks something like this:

v=spf1 include:_spf.google.com ~all

SPF is commonly used together with another email verification technology called DKIM. Having both enabled on your domain greatly improves security and email deliverability.

What is DKIM?

DomainKeys Identified Mail (DKIM) lets organisations take responsibility for the messages they send and guarantee their contents. This helps prevent spoofing, where email content is changed to make a message appear to come from someone or somewhere other than the actual source.

DKIM adds an encrypted signature to the header of every outgoing message. Email servers that receive these messages use the public DKIM key to decrypt the header and verify that the message wasn’t changed after it was sent. You can learn more about DKIM at dkim.org, where the group that developed the standard has published detailed explanations, how-tos and news.

Once SPF and DKIM are configured on your domain, you need to tell other mail servers how to react when an email from your domain fails either check.

What is DMARC?

Domain-based Message Authentication, Reporting and Conformance (DMARC) isn’t an email authentication protocol itself, but it builds on the key authentication standards, SPF and DKIM.

DMARC lets an organisation publish a policy that defines its email authentication practices and tells receiving mail servers how to enforce them.

To enable DMARC, you add a TXT record to your DNS configuration. First make sure that both SPF and DKIM are configured for your domain.

Here’s an example DMARC policy that rejects 100% of messages that fail the DMARC check and emails a daily report to two addresses:

v=DMARC1; p=reject; rua=mailto:postmaster@domain.com, mailto:admin@domain.com

Get expert advice

Have you been a victim of email fraud, or do you suspect your business might be vulnerable? Are you doing enough to protect your business, clients and suppliers against these social engineering attacks?

We’re ready to help. Contact us for a free domain audit and advice on protecting your employees and clients.

Ready to move to Google Workspace?

Get a migration assessment from the cozan team.