Email Security Beyond Phishing: SPF, DKIM, and DMARC Explained for Small Businesses

SPF, DKIM, and DMARC email security for a small business

Most cybersecurity advice for small businesses focuses on what your people should do. Don't click suspicious links. Use the SLAM method. Enable MFA. All good advice, and we have written about all of it.

But there is a whole other layer of email security that has nothing to do with your team. It is the part that protects your domain from being impersonated. And it is the part that almost every small business in Gwinnett County is either ignoring or has set up wrong.

This post explains SPF, DKIM, and DMARC in plain English. What they do, why they matter, how to know if yours are configured correctly, and how to roll them out without accidentally breaking your email.

Why You Should Care

Here is the scenario this protects against. Someone outside your company sends an email that looks like it came from you (or from your CEO, your bookkeeper, your owner). The "From" address says yourbusiness.com. The email asks a vendor to wire money, or asks an employee to buy gift cards, or asks a client to update their payment details.

That is business email compromise (BEC). According to the FBI's Internet Crime Complaint Center, BEC scams cost US businesses $2.9 billion in 2024 — and most of those victims are small and mid-sized businesses, not Fortune 500s. We covered the broader phishing landscape in our types of phishing attacks post.

Here is what makes BEC so effective: by default, the email protocol from the 1980s does nothing to verify that the sender actually owns the domain in their "From" address. Anyone with basic technical skill can send an email that says it is from your CEO. SPF, DKIM, and DMARC are the three pieces of plumbing that fix that.

There is a second reason to care: your cyber insurance carrier is starting to ask. Renewal questionnaires now include questions like "Is DMARC enforced (p=reject) on your domain?" If you say no, you may not get coverage, or you will pay a higher premium. We have seen this with multiple Lawrenceville and Gwinnett-area businesses in the last year.

What Each Record Actually Does

These are three separate DNS records that live on your domain. They work together but each does something different. The DMARC.org overview is a good free reference if you want to dig deeper.

SPF (Sender Policy Framework)

SPF is a list of servers that are allowed to send email on behalf of your domain.

When you set up SPF, you publish a TXT record on your domain that says something like "Microsoft 365, Mailchimp, our QuickBooks Online server, and our managed IT provider's helpdesk system are the only servers allowed to send mail as @yourbusiness.com."

When someone receives an email claiming to be from you, their mail server checks: did this email come from one of the servers on your SPF list? If yes, good. If no, it is suspicious.

The catch with SPF on its own: it only checks the "envelope sender" (the technical sender used for bounce-back routing), not the "From" address the user actually sees. So SPF by itself doesn't fully protect against spoofing. It is necessary but not sufficient.

DKIM (DomainKeys Identified Mail)

DKIM is a digital signature on each email you send. Every email gets cryptographically signed by your mail server using a private key. The public key is published in your DNS so receiving servers can verify the signature.

If the signature checks out, the receiver knows two things: the email came from your mail server, and nobody modified it in transit.

Why DKIM matters: it proves the email is authentic, even if it was forwarded. Without DKIM, anyone can claim to be your domain.

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

DMARC is the policy layer that ties SPF and DKIM together. It tells receiving servers what to do when an email fails SPF or DKIM checks.

A DMARC policy has three settings:

  • p=none: "Just monitor and tell me about failures, don't block anything." Useful for the first 30-60 days while you figure out what is actually sending email as you.
  • p=quarantine: "If an email fails authentication, send it to the spam folder."
  • p=reject: "If an email fails authentication, refuse to deliver it at all."

DMARC also includes reporting. Receiving servers send daily reports to an email address you specify, showing every authentication failure that happened. This is gold for spotting either spoofing attempts or legitimate services that need to be added to your SPF/DKIM. CISA published a free guide to email authentication that covers this in detail.

The Three Stages of Rollout

Here is how a real DMARC rollout goes. Skipping stages will break your email, so go in order.

Stage 1: Set up SPF and DKIM, with DMARC in monitor mode

First, make sure SPF and DKIM are configured for every service that legitimately sends email as your domain. The usual suspects:

  • Microsoft 365 or Google Workspace (your main email)
  • Your marketing email tool (Mailchimp, Constant Contact, ActiveCampaign, etc.)
  • Your CRM or sales tool (HubSpot, Salesforce, Zoho)
  • Your accounting software (QuickBooks Online, Bill.com)
  • Your appointment booking tool (Calendly, Acuity)
  • Your help desk or ticketing system
  • Any payroll, benefits, or HR platform that emails on your behalf
  • Your e-signature platform (DocuSign, Adobe Sign)

Each of those services has a help page explaining the SPF include and DKIM CNAME records to add to your DNS. Add them all.

Then publish a DMARC record with p=none and a reporting email. That gives you 30 days of visibility into what is actually being sent.

Stage 2: Move to p=quarantine

After you have reviewed reports and confirmed all legitimate senders are authenticated, change DMARC to p=quarantine. Now any email that fails (likely spoofing attempts) goes to spam instead of inbox.

Stay here for another 30 days. Watch for legitimate email getting caught. Fix any sender you missed.

Stage 3: Move to p=reject

This is enforcement. Any email failing SPF or DKIM gets refused outright. Spoofing attempts using your domain are now blocked at the receiving server, before they ever reach your customer or your vendor.

This is the level most cyber insurance carriers want to see. It is also the level that actually protects your brand and your customers.

Common Mistakes We See

  • Setting up DMARC at p=reject on day one. This will break legitimate email from services you forgot about. Always go through monitor mode first.
  • Forgetting marketing tools. Mailchimp, Constant Contact, and similar tools need SPF includes and DKIM CNAME records. If you set up DMARC without authenticating these, your marketing emails will hit spam.
  • Multiple SPF records. Your domain can only have one SPF TXT record. If you have two, some receivers will fail both. Consolidate into one.
  • SPF lookup limit. SPF allows a maximum of 10 DNS lookups per record. If your includes go over that, SPF fails. We see this with businesses that have piled up many marketing tools.
  • No DMARC reporting address. Without a reporting address, you have no visibility into what is failing or who is spoofing you. Use a dedicated mailbox or a service like Postmark, Valimail, or dmarcian to parse the reports.
  • Setting it up and never checking again. DNS records do not expire, but the services that send mail on your behalf change. Audit your authentication setup at least annually. Our managed cybersecurity service includes a quarterly review of email authentication for exactly this reason.

Not Sure Where Your Domain Stands?

We do free DMARC audits for businesses in the Atlanta and Gwinnett County area. We'll pull your current SPF, DKIM, and DMARC records and tell you exactly what's missing or misconfigured.

Book a Discovery Call

How to Check Your Current Setup

If you want a quick check before talking to anyone, here are two free tools.

MXToolbox (mxtoolbox.com): Plug your domain into their SPF, DKIM, and DMARC checkers. It will tell you what records you have, whether they are valid, and what they look like.

Google Postmaster Tools (postmaster.google.com): If you have any volume of email going to Gmail recipients (most of us do), this tool shows you authentication pass rates from Google's perspective.

If those tools show you have no DMARC record, or your DMARC is set to p=none with no reporting, you have got real work to do.

What This Costs

The DNS changes themselves cost nothing. They are text records you publish on the domain you already own.

If you want a DMARC reporting and management service to make sense of the reports, expect $0-$50/month for a small business. Tools like dmarcian, Valimail Monitor, Postmark, and EasyDMARC all have free or low-cost tiers for small business volumes.

If your IT provider sets it all up for you, that is usually 4-8 hours of work spread across the three-stage rollout. Often included in a managed IT engagement. At NGT we include it as part of our standard onboarding for new managed IT clients. If you already have an internal IT person who could use backup on the heavier security pieces, our co-managed IT service covers exactly that.

A Few Common Questions

If you do it in the three-stage rollout described above, no. The whole point of starting at p=none is to find every legitimate sender before you start blocking anything.
Microsoft 365 sets up SPF and DKIM for the mail you send through Microsoft's servers. But it does not set up SPF includes for every other service that sends mail as you (Mailchimp, QuickBooks, etc.), and it does not publish a DMARC record by default. You still need to do that piece. We covered the broader Microsoft 365 picture in our migration guide and the license audit post.
Same answer. Google authenticates its own outbound mail but doesn't manage your full sender list or your DMARC policy.
Usually 60-90 days from start to enforcement, if nothing weird comes up in monitoring. We have done it faster for simple environments and slower for businesses with a lot of marketing tools.
Be honest. If you are at p=none or no DMARC, say so, and tell them you are rolling out enforcement on a 60-day timeline. Most carriers are fine with a plan in progress. They are not fine with "we'll get to it." Industries with carrier scrutiny (especially law firms, insurance agencies, and CPA firms) should treat this as a now problem.

The Bottom Line

SPF, DKIM, and DMARC are not optional anymore. They are table stakes for email security in 2026, your cyber insurance carrier is going to start asking, and the cost of not having them is real (BEC attacks against businesses just like yours).

If your IT provider hasn't talked to you about email authentication, ask them about it this week. If you are not sure who to ask, that is what we are here for. NGT Technology helps Gwinnett County and metro Atlanta small businesses lock down their email every day.

Martin Gonzalez
Founder & CEO, NGT Technology

Martin has been helping Georgia businesses with their IT for over 17 years. He holds certifications in Microsoft, Azure, and AWS technologies, and founded NGT Technology in Lawrenceville, GA to give small businesses access to enterprise-grade IT support without the enterprise price tag.

Related Posts

Get Your Email Authentication Locked Down

A discovery call from NGT Technology includes a free SPF, DKIM, and DMARC audit. We'll pull your current records, identify gaps, and lay out a 60-day plan to get you to p=reject without breaking a single email.

Email security and DMARC for small businesses