Cyber Security
Can Someone Pretend to Be Your Business?
How DMARC helps protect your customers and your reputation
8 min read — Altitude IT Security Team
Imagine one of your customers receives an email that appears to come from your business. It uses your company name, your domain, your branding and your email address. The message asks them to pay an invoice, open an attachment, click a link or update their account details.
To your customer, it looks genuine. But it wasn't sent by you.
This is email spoofing, and it has become one of the most common techniques used in phishing and Business Email Compromise attacks. The good news is that a well-established set of email authentication standards — SPF, DKIM and DMARC — makes it much harder for anyone to send email pretending to be you.
The Quick Answer
DMARC is an email authentication standard that helps receiving email systems identify messages that genuinely come from your domain — and reject or quarantine those that do not. It works alongside two other standards, SPF and DKIM.
DMARC helps reduce domain impersonation and improve email deliverability. However, it is only one part of a wider email security strategy.
What Is Email Spoofing?
Email was designed decades ago, when the internet was a much more trusting place. By default, there is nothing stopping someone putting your email address in the "from" field of a message they send — in the same way anyone can write your return address on the back of an envelope.
Criminals take advantage of this to make emails appear to come from a legitimate business. For your organisation, the risks include:
- Invoice fraud: customers or suppliers paying money into a criminal's account, believing the request came from you.
- Phishing: your name being used to trick people into handing over passwords or sensitive information.
- Reputation damage: your business becoming associated with scam emails you never sent.
- Customer trust: customers becoming wary of opening genuine emails from you.
- Supplier fraud: fraudulent instructions being sent to your suppliers in your name.
How SPF, DKIM and DMARC Work Together
Three standards work together to prove that an email genuinely came from your business. Each answers a different question:
- SPF — Checks whether the server sending the email is authorised to send on behalf of your domain.
- DKIM — Adds a digital signature to each message, confirming it has not been altered on the way to the recipient.
- DMARC — Tells receiving email systems what to do if those checks fail, and provides reporting so you can see who is using your domain.
When all three are configured correctly, receiving systems can confidently distinguish your genuine email from impersonation attempts.
What DMARC Protects
A correctly implemented DMARC policy can help your business:
- Reduce impersonation of your domain
- Improve your sender reputation
- Improve inbox placement of genuine email
- Protect your customers from spoofed messages
- Protect your suppliers from fraudulent requests
- Protect your staff from internal-looking spoofs
- See who is sending email on behalf of your organisation
What DMARC Does NOT Protect
DMARC is valuable, but it is important to be honest about its limits. DMARC does not:
- Encrypt your email
- Stop malware
- Stop users clicking phishing links
- Replace Microsoft Defender
- Replace multi-factor authentication
- Replace backups
- Replace staff awareness training
- Guarantee email delivery
Good cyber security uses multiple layers. DMARC closes one important door — domain impersonation — but it works best as part of a broader strategy.
Why Proper Configuration Matters
Implementing DMARC is not simply a matter of adding a DNS record and moving on. Most businesses send email from far more places than they realise. Alongside Microsoft 365 or Google Workspace, legitimate email may also be sent by CRM systems, marketing platforms, website contact forms, finance software, printers, scanners and third-party cloud services.
Every one of those services needs to be identified and correctly authorised. Moving too quickly to a strict "reject" policy can unintentionally block legitimate messages — invoices that never arrive, enquiry forms that go silent, statements that vanish. A careful, staged implementation avoids these surprises.
Why Ongoing Monitoring Is Essential
Email authentication is not a one-off project. Every time your business introduces a new supplier, a CRM, a marketing platform, a new website, changes in Microsoft 365 or Google Workspace, finance software or cloud applications, your email authentication configuration may need reviewing.
Email authentication is most effective when it forms part of an Operational Heartbeat, with regular reviews of authentication records, authorised senders and DMARC reports.
How Altitude Helps
Altitude works with businesses in plain English, with a practical, security-focused and outcome-driven approach. We can help you:
- Review your existing email authentication
- Identify gaps and unauthorised senders
- Configure SPF and DKIM correctly
- Implement DMARC in careful stages
- Review and interpret DMARC reports
- Improve Microsoft 365 email security
- Improve Google Workspace email security
- Investigate deliverability issues
- Provide ongoing Operational Heartbeat reviews
The precise recommendations depend on your existing systems and how your organisation sends email. Our aim is not simply to publish a DMARC record, but to make sure it continues working as your business evolves.
Frequently Asked Questions
- What is DMARC?
- DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard. It tells receiving email systems what to do with messages that claim to come from your domain but fail authentication checks, and it provides reports so you can see who is sending email using your domain.
- What is SPF?
- SPF (Sender Policy Framework) is a DNS record that lists the servers and services authorised to send email on behalf of your domain. Receiving systems check it to see whether a message came from an approved source.
- What is DKIM?
- DKIM (DomainKeys Identified Mail) adds a digital signature to your outgoing email. Receiving systems use it to confirm the message genuinely came from your domain and was not altered in transit.
- Why do I need all three?
- SPF and DKIM each answer part of the question "is this email genuine?". DMARC brings them together: it tells receiving systems what to do when checks fail, and gives you reporting. Without DMARC, spoofed messages that fail SPF or DKIM may still be delivered.
- Can someone spoof my business email?
- If your domain does not have properly configured SPF, DKIM and DMARC, it is technically straightforward for someone to send email that appears to come from your domain. Authentication makes this far harder to do successfully.
- Does DMARC stop phishing?
- DMARC helps reduce one specific technique — direct spoofing of your domain. It does not stop phishing emails sent from look-alike domains or compromised accounts, so it should sit alongside filtering, MFA and staff awareness training.
- Can DMARC improve deliverability?
- Yes. Major email providers increasingly favour authenticated email, and some now require it for bulk senders. Correctly configured SPF, DKIM and DMARC can improve the chances of your legitimate email reaching the inbox.
- Does Microsoft 365 support DMARC?
- Yes. Microsoft 365 fully supports SPF, DKIM and DMARC, and honours DMARC policies on inbound email. DKIM signing for your domain usually needs to be enabled and configured — it is not always on by default.
- Does Google Workspace support DMARC?
- Yes. Google Workspace supports SPF, DKIM and DMARC, and Google is one of the providers that now expects authentication from senders. Configuration is done through your DNS records and the Google Admin console.
- How often should DMARC be reviewed?
- Whenever your business changes how it sends email — a new CRM, marketing platform, website or finance system — and on a regular schedule in between. Reviewing DMARC reports periodically helps you spot unauthorised senders and misconfigured services early.
- What happens if I move to reject too quickly?
- Legitimate email can be blocked. Many businesses have services they have forgotten about — contact forms, scanners, invoicing tools — that send email on their behalf. A staged rollout, starting with monitoring, avoids disrupting genuine messages.
- Can Altitude help configure DMARC?
- Yes. Altitude can review your existing email authentication, configure SPF, DKIM and DMARC, support a staged implementation and provide ongoing reviews of your DMARC reports. The precise recommendations depend on your existing systems and how your organisation sends email.