Glossary
DMARC, SPF & DKIM
Three complementary standards that prove an email actually comes from your domain and prevent attackers from impersonating you.
If your domain isn't protected by SPF, DKIM, and DMARC, anyone can send email pretending to be you — your name, your address, your signature. Your customers receive fake invoices "from you", your suppliers receive fraudulent bank-account changes, and you discover the problem only when money is gone.
SPF (Sender Policy Framework) lists which servers are authorised to send email on your behalf. DKIM (DomainKeys Identified Mail) cryptographically signs each legitimate message. DMARC (Domain-based Message Authentication, Reporting & Conformance) tells receiving servers what to do if SPF or DKIM fails: ignore, mark as spam, or reject.
The goal is to reach DMARC in p=reject mode. The standard rollout is progressive: p=none (observe, 30 days), then p=quarantine (mark as spam, 30 days), then p=reject. Each step is verifiable via a free tool like mxtoolbox.com.