DMARC, SPF and DKIM Cybersecurity Explained: What Does a Domain Check Uncover?

What can a Domain Check reveal about your business? Learn what DMARC, SPF and DKIM mean, how they protect your email domain from impersonation, what your Domain Check score and risk rating tell you, and what to do if potential security weaknesses are identified.

What can your company domain reveal about your cybersecurity?

 

Your company domain can reveal more about your cybersecurity than you might realise.

A Domain Check looks at publicly available information associated with your domain to uncover potential security gaps, particularly around how your business email is authenticated and protected against impersonation.

Why does that matter? Because criminals can use weaknesses in email authentication to make fraudulent emails appear more convincing, putting your firm’s reputation, client relationships and potentially sensitive information at risk.

A Domain Check may include an overall security score and risk rating, alongside terms such as DMARC, SPF and DKIM.

But what do those results actually mean? Is a lower score something to worry about? And what should you do if the check uncovers a weakness?

Here, we’ll explain what a Domain Check can uncover, what DMARC, SPF and DKIM actually do, and how to interpret the results.

What is a Domain Check?

 

Your domain is the part of your email address that comes after the @ symbol, for example, yourcompany.co.uk. It’s an important part of your organisation’s digital identity.

A Domain Check examines publicly available security information associated with that domain. It can identify potential weaknesses in email authentication and provide an indication of how well your domain is protected against certain forms of email impersonation.

A Domain Check will look at three specific areas:

  • SPF: Sender Policy Framework
  • DKIM: DomainKeys Identified Mail
  • DMARC: Domain-based Message Authentication, Reporting and Conformance

Together, they help receiving email systems answer an important question:

“Is this email really coming from an authorised sender for this business?”

Why does that matter?

 

Imagine one of your clients receives an email that appears to come from someone at your business:

“We’ve changed our bank details. Please use this account for your outstanding invoice.”

Or one of your employees receives what appears to be an email from a director:

“I’m in meetings this afternoon. Can you make this payment urgently and confirm when it’s done?”

Clients may routinely receive invoices, confidential documents, financial information and important information from your domain. Cybercriminals can exploit that trust by impersonating organisations or individuals.

Email authentication technologies such as SPF, DKIM and DMARC are designed to make impersonation more difficult.

What does SPF mean in cybersecurity?

 

SPF stands for Sender Policy Framework.

Think of it as an authorise-senders list for your domain.

Your business may send email through Microsoft 365 or Google Workspace, but those probably aren’t the only systems sending email on your behalf. Your CRM, website, accounting software, marketing platform and other cloud applications might send email using your domain too. SPF helps specify which systems are authorised to do that.

If a Domain Check shows that SPF is valid, that’s a positive sign. It means an SPF record has been identified and passes the check being performed. However, SPF is only one part of email authentication.

What does DKIM mean?

 

DKIM stands for DomainKeys Identified Mail.

DKIM uses a digital structure to help receiving systems verify email associated with your domain. In simple terms, it provides another way of establishing that an email is legitimate and hasn’t been altered in transit.

If a Domain Check shows DKIM as valid, that’s another positive result.

But having SPF and DKIM in place doesn’t necessarily mean your email authentication is as strong as it could be. That’s where DMARC becomes particularly important.

What does DMARC mean?

 

DMARC stands for Domain-based Message Authentication, Reporting and Conformance.

Working with SOF and/or DKIM, DMARC checks whether the authenticated domain appropriately aligns with the domain the recipient sees in the ‘from’ address. It can also tell receiving email systems what to do when messages claiming to come from your domain don’t pass the appropriate authentication checks.

This is where you may see terms such as:

  • p=none
  • p=quarantine
  • p=reject

They’re different DMARC policy policy levels.

p=none

Is essentially a monitoring policy.

DMARC is in place, but the policy doesn’t instruct receiving systems to quarantine or reject messages that fail DMARC checks.

p=quarantine

Asks receiving systems to treat failing messages as suspicious, typically making them candidates for spam or quarantine.

p=reject

Is the strongest of these enforcement policies and asks receiving systems to reject messages that fail DMARC.

That doesn’t mean every business should simply change from p=none to p=reject immediately. Doing so without understanding all the legitimate systems sending email on behalf of your organisation can disrupt business communications.

Moving towards stronger DMARC enforcement should be carried out carefully.

What does your overall Domain Check score mean?

 

Your score gives you an at-a-glance indication of the findings identified by the Domain Check. But don’t focus on the number alone.

Whatever score you receive, don’t interpret it as a percentage measure of your company’s overall cybersecurity. A Domain Check looks at specific aspects of your domain security, it isn’t assessing every part of your IT environment. Likewise, receiving a Medium or High risk rating doesn’t mean that you’ve suffered a cyberattack.

The important part is understanding why you’ve received that score or risk rating.

You might have valid SPF and DKIM records but a DMARC configuration that could be strengthened.

Another organisation might have entirely different issues.

So rather than asking:

“How do we get our score to 10?”

A better question is:

“What has the check identified, what risk does it create, and what should we do about it?”

Does a poor result mean you've been hacked?

 

No. A Domain Check identifies potential security weaknesses, it isn’t evidence by itself that somebody has compromised your systems. That’s an important distinction.

Think of it a little like checking the doors and windows of a building. Finding that a window isn’t secured as well as it could be doesn’t mean somebody has broken in.

But once you know about it, you’d probably want to understand the risk and decide whether something needs changing.

Does a good Domain Check score mean you're cyber secure?

 

Unfortunately, no. DMARC, SPF and DKIM deal with a specific part of your security posture. A business could have strong email authentication and still have vulnerabilities elsewhere.

For example, a Domain Check doesn’t tell you the whole story about how well your employees’ accounts are protected, whether credentials associated with your organisation have previously been exposed, how devices are secured, or how your organisation would respond to an active cyberattack.

That’s why a Domain Check should be viewed as one useful indicator of your cybersecurity posture, but no the entire pitcure.

What should you do it if your Domain Check identifies a problem?

 

First, don’t panic. Second, don’t start changing DNS or DMARC settings simply to make a warning disappear.

Instead, establish:

  1. What has actually caused the warning or lower score?
  2. Which systems legitimately send email using your domain?
  3. Are SPF and DKIM correctly configured for those systems?
  4. What DMARC policy is currently in place?
  5. Can protection be strengthened safely without disrupting legitimate email?

The aim isn’t simply to turn an amber result green, it’s to make sure the underlying risk is properly understood and addressed.

What should you do next?

 

A Domain Check gives you visibility into one part of your cybersecurity. It may uncover something worth investigating, but it can’t tell you everything about the security of your business.

If a weakness has been identified, the important thing is to understand what has caused it, what risk it creates and whether anything needs changing.

From there, there are several possible next steps.

Start with a conversation

 

If we’ve provided you with a Domain Check, we’re happy to talk you through it.

We can explain your score and risk level, what has been identified with your DMARC, SPF or DKIM configuration, and whether there are any actions we would recommend.

You don’t need to understand the technical detail. The purpose of the conversation is simply to help you understand the findings and decide whether anything else needs attention.

Book a call

Take our Cyber Assessment

 

Your Domain Check only looks at one part of your cybersecurity.

If you’re not sure how well protected your organisation is more broadly, our quick ten question Cyber Assessment can help you look beyond email authentication and identify other areas that may warrant attention.

Instead of simply asking “Is our domain properly protected?” you can quickly gain a clear picture of where your cybersecurity currently stands. You’ll receive a personalised cybersecurity score, an analysis of your results and practical recommendations showing where to focus next.

Take the Cyber Assessment

Consider further security testing

 

Sometimes there is good reason to look deeper. You may have concerns about other vulnerabilities, requirements from clients or insurers, or want independent evidence of how your existing security measures would stand up to an attack.

In those circumstances, we may recommend further security testing, such as a penetration test. It won’t be necessary for every organisation, which is why we’d rather understand your circumstances first and recommend the appropriate next step.

The goal is confidence, not fear

 

A Domain Check can uncover something you weren’t aware of, but its value isn’t in giving you another cybersecurity issue to worry about. It’s giving you information you can act on.

Cybersecurity should be about knowing where you stand. Do you understand your risks? Are sensible protections in place? Are there gaps that need attention? And if something did happen, could you detect it and rapidly respond?

For professional services organisations, being able to answer those questions confidently matters. You’re not just protecting your own business and reputation; you’re protecting your clients too.

That’s the thinking behind our approach to Cyber Confidence: helping you understand your current position, identify what needs attention and make sensible decisions about what to do next.

Received a Domain Check from us?

Take the opportunity to understand what the findings mean and whether there are other gaps in your cybersecurity that deserve attention.