Перейти к содержанию
Экстренная линия 24/7
ru
Услуги
Решения
Исследования
Компания
ИнструментыTrust Center

25 сентября 2026 г.Отчёты и руководства

Что такое DMARC? Как остановить подделку почты с SPF, DKIM и DMARC

Email was never designed to verify who the sender is. SPF, DKIM and DMARC are the three layers that close that gap — and they only make sense together.

2 мин чтения

Этот материал пока доступен только на английском языке.

The problem: anyone can write the “From” line

An email's “From” line is like the return address on an envelope: you can write anything. That's why attackers impersonate a supplier, a bank or the CEO to request invoice payments, password resets or urgent transfers.

Why it matters

Business email compromise (BEC) needs no technical exploit. All it takes is a sender address the recipient believes.

Three layers, three different questions

ControlQuestion it answersWhere it's published
SPFIs this server allowed to send mail for this domain?The domain's TXT record
DKIMWas the message signed with the domain owner's key and left unchanged in transit?selector._domainkey TXT record
DMARCDoes SPF or DKIM align with the visible “From” domain? If not, what should happen?_dmarc TXT record

SPF and DKIM alone are not enough, because neither checks the “From” address the user sees. Alignment is what makes DMARC valuable: the authenticated domain must match the domain on screen.

Example records

example.com.          TXT  "v=spf1 include:_spf.google.com include:mailgun.org -all"
_dmarc.example.com.   TXT  "v=DMARC1; p=reject; rua=mailto:[email protected]; adkim=s; aspf=s"
  • SPF: There must be a single record and no more than 10 DNS lookups. Every new sending service (CRM, invoicing, marketing) must be added.
  • DKIM: Enabled in your provider's console; keys should be at least 2048 bits and rotated periodically.
  • DMARC: p= sets the policy and rua= the address for aggregate reports.

Moving safely from p=none to p=reject

  1. 01

    Monitor (p=none)

    Publish DMARC with a reporting address. Over a few weeks, list every source sending mail in your name from the reports.

  2. 02

    Fix

    Add each legitimate source to SPF or have it sign with DKIM. A forgotten CRM or newsletter tool is the most common problem.

  3. 03

    Quarantine (p=quarantine)

    Unaligned mail goes to spam. Watch the reports for unexpected legitimate sources.

  4. 04

    Reject (p=reject)

    Spoofed mail is refused outright by receivers. This is the goal.

Check yours

See your domain's current state in seconds with the Email Security Analyzer.

What DMARC can't protect

DMARC only stops spoofing of your own domain. If an attacker registers a look-alike such as “example-support.com”, that domain can have flawless SPF and DMARC of its own. Scan for these with the Phishing Risk Checker, and use our brand protection service for continuous monitoring.

For an end-to-end review of your corporate email infrastructure, see our Email Security service.

Давайте вместе определим объём работ.

Расскажите о задаче — наши специалисты подготовят индивидуальное предложение.

Все исследования