4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

SPF, DKIM & DMARC Explained for Australian SMEs | 4iT

SPF, DKIM, and DMARC are three email authentication standards that together prove your emails really do come from your domain and stop criminals sending fake emails in your name. For an Australian SME they matter for two reasons: they protect your business from being impersonated in scams, and without them your legitimate email increasingly lands in spam or gets rejected. Setting all three up correctly is one of the highest-value, lowest-cost security jobs a business can do.

Laptop showing an email inbox with authentication settings on screen

Key facts

  • SPF, DKIM, and DMARC are DNS-based standards that let receiving mail servers verify an email really came from your domain.
  • SPF lists which servers may send email for your domain; DKIM adds a tamper-proof signature; DMARC ties them together and tells receivers what to do with mail that fails.
  • Without DMARC set to enforce, anyone can send email that appears to come from your domain, which is the basis of many impersonation scams.
  • Major providers including Google and Microsoft now require SPF, DKIM, and DMARC for bulk senders, and increasingly filter or reject mail from domains without them.
  • Business email compromise, often starting with domain impersonation, is among the costliest cybercrimes reported by Australian businesses (ASD Annual Cyber Threat Report 2024-25).

What are SPF, DKIM, and DMARC?

They are three complementary email authentication standards, published as records in your domain's DNS, that let any receiving mail server check whether an email claiming to be from your domain is genuine. Think of them as three layers of the same lock. On their own each is useful but incomplete; together they close the gap that lets attackers forge email in your name. All three are configured once in your DNS and then work automatically for every email your domain sends, which is why getting them right matters: a mistake affects all your mail, and so does getting them right.

What does SPF do?

SPF (Sender Policy Framework) is a DNS record that lists the mail servers allowed to send email on behalf of your domain. When a receiving server gets an email claiming to be from you, it checks the SPF record to see whether the server that sent it is on the approved list. If a message comes from a server not on the list, that is a signal it may be forged. The common failure we see is an SPF record that has not kept up with reality: a business adds a new email marketing tool or a CRM that sends email, forgets to add it to SPF, and suddenly legitimate mail starts failing. SPF needs to reflect every service that sends email as your domain.

What does DKIM do?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every email your domain sends, which the receiving server checks against a public key published in your DNS. If the signature matches, the receiver knows two things: the email did come from your domain, and it was not altered in transit. Where SPF checks which server sent the mail, DKIM checks that the mail itself is authentic and untampered. The two answer different questions, which is why you want both. DKIM is normally enabled in your email platform (Microsoft 365 or Google Workspace) and paired with a DNS record, and once set up it signs everything automatically.

What does DMARC do, and why is it the important one?

DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together and tells receiving servers what to do when an email fails those checks. This is the piece that stops impersonation. A DMARC record can be set to three policies: none (monitor only, do nothing), quarantine (send failing mail to spam), or reject (block failing mail outright). Many businesses set up SPF and DKIM but leave DMARC at none, or never set it up at all, which means forged email in their name still gets delivered. The protection only kicks in when DMARC is set to quarantine or reject. DMARC also sends you reports showing who is sending email using your domain, which often reveals both legitimate services you had forgotten and attackers attempting to impersonate you. Moving to enforcement should be done carefully, starting at none to gather reports, because switching straight to reject without checking can block your own legitimate mail.

Do small businesses really need all three?

Yes, and the pressure to have them is now coming from the big email providers, not just security best practice. Google and Microsoft have moved to require SPF, DKIM, and DMARC for senders, and mail from domains without proper authentication is increasingly filtered to spam or rejected. So there are two payoffs. The security payoff is that a correctly enforced DMARC policy stops criminals sending scam emails that appear to come from your business, protecting your customers and your reputation. The deliverability payoff is that your genuine email reaches inboxes. In our experience, most SMEs we onboard have SPF in some form, patchy or missing DKIM, and DMARC either absent or stuck on none, which means they have the appearance of email security without the protection. Fixing that is usually a quick, high-value job. You may also want to understand how email spam filtering works and consider phishing simulation to test your staff alongside these technical controls.

Frequently asked questions

What is the difference between SPF, DKIM, and DMARC?

SPF lists which servers are allowed to send email for your domain. DKIM adds a cryptographic signature proving an email is genuine and unaltered. DMARC ties the two together and tells receiving servers what to do with mail that fails, and sends you reports. You need all three: SPF and DKIM do the checking, and DMARC turns those checks into actual protection.

Will setting up DMARC block our own emails?

It can if you rush to a reject policy without checking first, which is why you start DMARC at a monitoring policy (none) to gather reports on everything sending mail as your domain. Once you have confirmed all your legitimate senders are covered by SPF and DKIM, you move to quarantine and then reject. Done in that order, enforcement protects you without blocking genuine mail.

Is email authentication mandatory in Australia?

There is no Australian law mandating it, but the major email providers effectively require it. Google and Microsoft now expect SPF, DKIM, and DMARC, particularly from bulk senders, and mail from domains without them is increasingly filtered or rejected. So while it is not a legal requirement, in practice it has become necessary for reliable email delivery as well as security.

How long does it take to set up?

The initial DNS records for SPF and DKIM can usually be configured quickly, often within a day, for a typical SME. The part that takes longer is DMARC: you run it in monitoring mode for a few weeks to confirm every legitimate sender is authenticated before moving to enforcement. Rushing that step is what causes problems, so the sensible timeline is quick setup followed by a short monitoring period.

If you are not sure whether your domain has SPF, DKIM, and DMARC set up correctly, or whether DMARC is set to enforce, that is a quick thing for us to check. Call 4iT on 1800 367 448 or book a chat and we will tell you where your email authentication stands and what to fix.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity and email security, including Microsoft 365 hardening, phishing simulation, and email authentication, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top