Let me ask you something: Have you ever sent a quote, invoice, or important project update, and then discovered your customer never saw it?
You check your Sent folder. The message left your mailbox. But your customer finds it three days later in spam… or not at all.
It feels like mailing a signed contract and watching it disappear somewhere between your office and the customer’s front door.
Of course, you would never send an invoice through an unlocked mailbox and hope it arrives safely. You would put your name on it, seal the envelope, and use a trusted delivery service.
Your business email needs the digital version of that process.
That is where SPF, DKIM, and DMARC come in. These three email authentication tools help receiving mail systems confirm that your messages are really from you, and help stop criminals from pretending to be you.
For small businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and throughout Missouri, email authentication is no longer a technical “nice to have.”
It is part of your security, your deliverability, and your reputation.
Why email authentication matters to your business
Think about the name on your email address.
If your customer receives a message from you@yourbusiness.com, they assume it came from your business. But without proper authentication, attackers may be able to send messages that appear to come from your domain even when they have never logged into your mailbox.
That is email spoofing.
A criminal can impersonate your domain, send a fake invoice, request a wire transfer, or tell your customer to “confirm” payment details. The customer sees your familiar business name and may not realize the message is fraudulent.
And here’s the other side of the problem: Authentication failures can also hurt legitimate messages.
Your real quote may look suspicious to Gmail, Microsoft 365, Yahoo, or another receiving system. The message may land in spam because the receiving server cannot confidently verify that your business authorized it.
Research shows the problem is widespread. Barracuda’s 2025 email threat research found that nearly half of companies had no DMARC policy, while only about 23% had DMARC at an enforcement level.
That means many organizations are still telling receiving mail systems, “Please watch this,” instead of, “Block messages that fail.”
Another analysis reported that fully authenticated senders with enforced DMARC were about 2.7 times more likely to reach the inbox than unauthenticated senders. In plain English, authentication can help your good email get recognized, and make it harder for criminals to misuse your domain.
SPF, DKIM, and DMARC in plain English
You do not need to become a DNS expert to understand the basics.
SPF: Who is allowed to send for you?
SPF stands for Sender Policy Framework.
Think of SPF as a guest list at your front door. It tells receiving mail systems which servers and services are allowed to send email using your domain.
Your business may send email through:
- Microsoft 365 or Google Workspace
- Your accounting or invoicing platform
- A customer relationship management system
- A marketing email service
- A support or ticketing system
- Your website contact form
If one of those legitimate services is missing from your SPF record, its messages may fail authentication.
There is a catch. SPF records can become too complicated when businesses keep adding vendors without cleaning up old entries. SPF also has a limit on DNS lookups, so “just add another sender” is not always the right fix.
DKIM: Did the message really come from your system?
DKIM stands for DomainKeys Identified Mail.
DKIM adds a digital signature to outgoing messages. The receiving mail system checks that signature against a public key published in your domain’s DNS.
Think of it like a tamper-evident seal on an envelope.
If the message was altered or did not come from an authorized system, the signature may fail. DKIM is especially important when you use third-party platforms that send email on your behalf.
Your IT provider should also review DKIM keys regularly and rotate them when appropriate. Old or exposed keys can weaken trust in your email system.
DMARC: What should happen when authentication fails?
DMARC stands for Domain-based Message Authentication, Reporting, and Conformance.
DMARC connects SPF and DKIM to your visible “From” address. It asks a simple question:
Does this message both pass authentication and align with the domain your customer sees?
Then DMARC tells the receiving mail system what to do when the answer is no.
There are three main policy stages:
- p=none: Monitor only. Failing messages are usually still delivered. This helps you learn what is sending email for your domain, but it does not provide meaningful blocking.
- p=quarantine: Treat failing messages as suspicious. They may be sent to spam or junk.
- p=reject: Reject failing messages outright. This provides the strongest protection against domain spoofing.
Here’s where many small businesses get stuck: They publish DMARC at p=none and never move forward.
Monitoring is a useful first step. It is not the finished security control.
Why this is a small-business problem
You may be thinking, “We only have 10 employees. Why would anyone target us?”
It makes sense to ask. But attackers often choose smaller organizations because they expect less monitoring, fewer security specialists, and faster payment decisions.
One convincing email can create several problems at once:
- A customer misses your quote because it lands in spam.
- An invoice is delayed because the recipient distrusts your domain.
- A fake vendor request sends money to the wrong account.
- A customer stops trusting your email address.
- Your team spends hours investigating messages that should have been easy to verify.
And here’s where it gets scary: DMARC can help block messages that spoof your domain, but it cannot stop every form of Business Email Compromise.
If an attacker steals a real mailbox, they may be able to send authenticated messages from the actual account. That is why email authentication should work alongside multi-factor authentication, secure access controls, employee awareness, and ongoing monitoring.
Our related guidance on Business Email Compromise and the risks facing small businesses explains why a realistic-looking request deserves a second verification step.
The practical path from p=none to p=reject
You do not have to switch everything overnight.
Start by building a clear picture of how your business sends email.
1. Inventory every sending source
Make a list of every system that sends messages using your domain.
Include your main mailbox platform, website, accounting software, CRM, marketing tools, appointment system, help desk, and any legacy server or device that sends notifications.
Forgotten systems are a common reason legitimate email breaks after authentication changes.
2. Clean up and align SPF
Review your SPF record for outdated services, duplicate entries, and syntax errors.
Your goal is not to include every service you have ever tried. Your goal is to authorize only the services that still send email for your business.
3. Confirm and rotate DKIM keys
Make sure each legitimate sending platform signs email with DKIM.
Your provider should confirm that the DKIM signature aligns with your domain and establish a reasonable key-rotation process. Rotation is like replacing the locks on a door before an old key has a chance to cause trouble.

4. Start DMARC with reporting
Publish DMARC at p=none with aggregate reporting.
These reports show which systems are sending email for your domain and whether messages pass SPF, DKIM, and alignment checks. They can reveal forgotten vendors, misconfigured websites, and unauthorized sending sources.
Do not ignore the reports. They are your map.
5. Move to quarantine, then reject
Once legitimate traffic is consistently passing, move to p=quarantine.
You can phase this in gradually while monitoring for customer-facing problems. After your provider confirms that legitimate messages pass reliably, move to p=reject.
That is the point where receiving systems are instructed to refuse messages that fail your domain’s authentication policy.
What to ask your IT provider this week
You do not need to troubleshoot DNS records alone. Ask your provider these questions:
- Which services currently send email using our domain?
- Is our SPF record valid, current, and within lookup limits?
- Are all legitimate senders using aligned DKIM signatures?
- When were our DKIM keys last reviewed or rotated?
- Do we have a DMARC record today?
- Is our DMARC policy set to
none,quarantine, orreject? - Who reviews our DMARC aggregate reports?
- What legitimate email could break if we increase enforcement?
- What is the timeline for moving from monitoring to rejection?
- How are MFA, mailbox rules, forwarding, and account takeover risks being monitored?
A good provider should answer in plain English and give you a plan, not just hand you three acronyms and walk away.
If your email system is part of a larger security review, Platinum Web Services cybersecurity solutions can help you connect email authentication with phishing protection, ransomware protection, MFA, and endpoint security.
Your email also depends on the systems behind it. Managed IT services, cloud services, network design and infrastructure, and reliable data recovery planning all support a stronger business security strategy.
Do not let your good email look like a threat
Your customers should not have to wonder whether your invoice is real.
Your employees should not have to guess whether a payment request came from a trusted vendor.
And criminals should not be able to borrow your business identity simply because your domain is missing a few basic safeguards.
SPF is your approved sender list. DKIM is your digital seal. DMARC is the instruction that tells receiving mail systems what to do when something fails.
Together, they help protect your reputation and keep legitimate business communication moving.
Platinum Web Services provides personalized St. Louis cybersecurity, St. Louis IT support for small business, Missouri managed IT services, St. Charles County IT support, Chesterfield IT services, Clayton IT consulting, O’Fallon IT support, and Metro East IT support with 24/7 availability.
If you would like help reviewing your email authentication, contact support@platinumwebservices.net.
Business hours: 24/7
Platinum Web Services
7827 Town Square Ave, 104-1184, O’Fallon, MO 63368


0 Comments