Dieser Inhalt ist derzeit nur auf Englisch verfügbar.
The problem: anyone can write the “From” line
An email's “From” line is like the return address on an envelope: you can write anything. That's why attackers impersonate a supplier, a bank or the CEO to request invoice payments, password resets or urgent transfers.
Why it matters
Business email compromise (BEC) needs no technical exploit. All it takes is a sender address the recipient believes.
Three layers, three different questions
| Control | Question it answers | Where it's published |
|---|---|---|
| SPF | Is this server allowed to send mail for this domain? | The domain's TXT record |
| DKIM | Was the message signed with the domain owner's key and left unchanged in transit? | selector._domainkey TXT record |
| DMARC | Does SPF or DKIM align with the visible “From” domain? If not, what should happen? | _dmarc TXT record |
SPF and DKIM alone are not enough, because neither checks the “From” address the user sees. Alignment is what makes DMARC valuable: the authenticated domain must match the domain on screen.
Example records
example.com. TXT "v=spf1 include:_spf.google.com include:mailgun.org -all" _dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:[email protected]; adkim=s; aspf=s"
- SPF: There must be a single record and no more than 10 DNS lookups. Every new sending service (CRM, invoicing, marketing) must be added.
- DKIM: Enabled in your provider's console; keys should be at least 2048 bits and rotated periodically.
- DMARC:
p=sets the policy andrua=the address for aggregate reports.
Moving safely from p=none to p=reject
- 01
Monitor (p=none)
Publish DMARC with a reporting address. Over a few weeks, list every source sending mail in your name from the reports.
- 02
Fix
Add each legitimate source to SPF or have it sign with DKIM. A forgotten CRM or newsletter tool is the most common problem.
- 03
Quarantine (p=quarantine)
Unaligned mail goes to spam. Watch the reports for unexpected legitimate sources.
- 04
Reject (p=reject)
Spoofed mail is refused outright by receivers. This is the goal.
Check yours
See your domain's current state in seconds with the Email Security Analyzer.
What DMARC can't protect
DMARC only stops spoofing of your own domain. If an attacker registers a look-alike such as “example-support.com”, that domain can have flawless SPF and DMARC of its own. Scan for these with the Phishing Risk Checker, and use our brand protection service for continuous monitoring.
For an end-to-end review of your corporate email infrastructure, see our Email Security service.
Lassen Sie uns den Umfang gemeinsam festlegen.
Schildern Sie uns Ihren Bedarf – unsere Spezialisten erstellen ein passendes Angebot.



