Why it matters
Fake emails are how most attacks start. Of the UK businesses that had a breach or attack in the last year, 85% had phishing: fake emails or messages. If someone can send email that looks like it came from you, they can trick your customers into paying them.
The three records, in plain words
- SPF: the list of services allowed to send email for your domain, such as your mailbox or your invoice tool.
- DKIM: a hidden signature on each email. It shows the email came from you and was not changed.
- DMARC: your rule for emails that fail. It can let them in and send you a report, send them to spam, or block them.
The order to do it in
- List every tool that sends email as you: your mailbox, your website forms, your invoices and your newsletters.
- Add SPF, and turn on DKIM in each of those tools.
- Add DMARC set to watch, and read the reports for a few weeks.
- When only your own tools pass, move to spam, then to block.
Who can do it
Whoever looks after your domain or email, often your IT provider. Each record is a short line of text at your domain provider. Adding it takes minutes. Moving to block needs care, so that your own emails keep arriving.
Sources
- Cyber Security Breaches Survey 2025. Department for Science, Innovation and Technology. Published 2025.
- Email security and anti-spoofing. National Cyber Security Centre. Published 7 October 2019.
Last checked: 4 October 2026.