Answers · Security

How do I stop people faking emails from my business?

The short answer

Add three records to your email domain: SPF, DKIM and DMARC. SPF lists who may send email for you. DKIM signs each email so it can be trusted. DMARC tells other mail servers what to do with an email that fails: let it in, send it to spam or block it. Start by watching, then block.

Why it matters

Fake emails are how most attacks start. Of the UK businesses that had a breach or attack in the last year, 85% had phishing: fake emails or messages. If someone can send email that looks like it came from you, they can trick your customers into paying them.

The three records, in plain words

  • SPF: the list of services allowed to send email for your domain, such as your mailbox or your invoice tool.
  • DKIM: a hidden signature on each email. It shows the email came from you and was not changed.
  • DMARC: your rule for emails that fail. It can let them in and send you a report, send them to spam, or block them.

The order to do it in

  • List every tool that sends email as you: your mailbox, your website forms, your invoices and your newsletters.
  • Add SPF, and turn on DKIM in each of those tools.
  • Add DMARC set to watch, and read the reports for a few weeks.
  • When only your own tools pass, move to spam, then to block.

Who can do it

Whoever looks after your domain or email, often your IT provider. Each record is a short line of text at your domain provider. Adding it takes minutes. Moving to block needs care, so that your own emails keep arriving.

Sources

  1. Cyber Security Breaches Survey 2025. Department for Science, Innovation and Technology. Published 2025.
  2. Email security and anti-spoofing. National Cyber Security Centre. Published 7 October 2019.

Last checked: 4 October 2026.

See where your business stands.

Type your website address and get a score and the three fixes that matter most. Free, with no sign-up.