
Someone Could Be Sending Emails as Your Business Right Now
Without any special tools, a scammer can put your domain in the From field, paste in your logo, and send one of your clients an email asking them to pay a fake invoice or update their banking details. The receiving mail server has no automatic way to know the message didn’t come from you.
This is called email spoofing, and it’s one of the most common starting points for business email compromise fraud in Australia. The ACSC flags it regularly in its annual cyber threat reports, and it’s directly relevant to your obligations under the Privacy Act and Notifiable Data Breaches scheme — because when a scammer impersonates your domain to defraud a client, that can quickly become your problem too.
The fix involves three DNS records. Most businesses have one or two of them in place. That’s usually enough of a gap for a spoofed email to get through.
The Three Records That Prove an Email Really Came from You
These records live in your domain’s DNS settings. You configure them once, and receiving mail servers check them on every message you send.
SPF — Who’s Allowed to Send on Your Behalf
SPF publishes a list of the mail servers authorised to send email for your domain. When a receiving server gets a message claiming to be from you, it checks whether the sending server is on that list. If it isn’t, SPF flags it.
DKIM — A Tamper-Proof Signature on Every Message
DKIM adds a cryptographic signature to your outgoing email. The receiving server uses a public key stored in your DNS to verify two things: the message genuinely came from your domain, and nothing was altered in transit. Microsoft 365 supports DKIM natively — it just needs to be enabled and configured for your domain.
DMARC — The Record That Actually Enforces the Rules
DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails authentication. It also checks that the domain visible in the From address matches what SPF and DKIM verified — which is what stops someone forging your exact address. As a bonus, it sends you reports showing every source sending email as your domain, including the ones that shouldn’t be.
The DMARC Setting Most Businesses Get Wrong
DMARC has three policy options, and this is where a lot of businesses stall:
- p=none — monitors and sends reports, but does nothing to block spoofed messages
- p=quarantine — sends failing messages to the recipient’s junk folder
- p=reject — blocks failing messages before they’re delivered
Many businesses set up DMARC at p=none, get reports for a while, and never move past it. At p=none, your domain is still wide open to spoofing. Real protection only begins at quarantine or reject.
Microsoft’s own guidance recommends working toward p=reject once you’ve confirmed your legitimate mail is passing authentication — which is why the rollout is done in stages, not all at once.
What These Records Won’t Stop
It’s worth being clear about the limits. SPF, DKIM, and DMARC protect your actual domain. They don’t protect against:
- Lookalike domains — a scammer registers something like
yourcompany-invoices.com.auand sends from that - Display-name spoofing — the From name reads “Accounts Team” but the actual address is a random Gmail account
For those, staff habits matter: always check the full email address, not just the display name, and verify any request to change payment details by calling a known number — not one provided in the email.
How to Check Where Your Domain Stands
Several free SPF and DMARC lookup tools let you type in your domain and see which records are present. That’s a useful starting point, though it won’t tell you whether the records are configured correctly.
The proper rollout looks like this:
- Publish SPF and DKIM covering all your legitimate sending sources (including Microsoft 365, any marketing platforms, and line-of-business apps)
- Add DMARC at
p=noneand review the reports - Move to
p=quarantine, thenp=reject, once your legitimate mail is consistently passing
Skipping straight to p=reject without checking first is what causes businesses to accidentally block their own emails.
Get Your Email Authentication Right
If you’re not sure whether your domain is properly protected — or you’ve had DMARC sitting at p=none for longer than you’d like to admit — we can help you sort it out properly.
Talk to The IT TechNinjas about getting SPF, DKIM, and DMARC configured correctly, or find out whether your business is ready to scale securely with our Safe to Scale assessment.
