What can your company domain reveal about your cybersecurity?
Your company domain can reveal more about your cybersecurity than you might realise.
A Domain Check looks at publicly available information associated with your domain to uncover potential security gaps, particularly around how your business email is authenticated and protected against impersonation.
Why does that matter? Because criminals can use weaknesses in email authentication to make fraudulent emails appear more convincing, putting your firm’s reputation, client relationships and potentially sensitive information at risk.
A Domain Check may include an overall security score and risk rating, alongside terms such as DMARC, SPF and DKIM.
But what do those results actually mean? Is a lower score something to worry about? And what should you do if the check uncovers a weakness?
Here, we’ll explain what a Domain Check can uncover, what DMARC, SPF and DKIM actually do, and how to interpret the results.
What is a Domain Check?
Your domain is the part of your email address that comes after the @ symbol, for example, yourcompany.co.uk. It’s an important part of your organisation’s digital identity.
A Domain Check examines publicly available security information associated with that domain. It can identify potential weaknesses in email authentication and provide an indication of how well your domain is protected against certain forms of email impersonation.
A Domain Check will look at three specific areas:
- SPF: Sender Policy Framework
- DKIM: DomainKeys Identified Mail
- DMARC: Domain-based Message Authentication, Reporting and Conformance
Together, they help receiving email systems answer an important question:
“Is this email really coming from an authorised sender for this business?”
Why does that matter?
Imagine one of your clients receives an email that appears to come from someone at your business:
“We’ve changed our bank details. Please use this account for your outstanding invoice.”
Or one of your employees receives what appears to be an email from a director:
“I’m in meetings this afternoon. Can you make this payment urgently and confirm when it’s done?”
Clients may routinely receive invoices, confidential documents, financial information and important information from your domain. Cybercriminals can exploit that trust by impersonating organisations or individuals.
Email authentication technologies such as SPF, DKIM and DMARC are designed to make impersonation more difficult.