Security

Can someone send email pretending to be your business?

Unless your domain publishes three short records, anyone can send an email that looks as if it came from you. Here is what they are and how to check yours.

Unless your domain says otherwise, anyone can send an email that appears to come from you. It takes no hacking: the sender's address on an email is just a line of text, as easy to fake as the return address on an envelope. Fraudsters use it to send fake invoices to your customers, ask your bookkeeper to change bank details or simply send spam in your name.

The fix is three short records in your domain's settings. Most businesses do not have all three. In a December 2025 check of almost 43,000 UK domains, three in four had no effective protection against this and nearly half had no record at all (DmarcDkim.com).

The three records, in plain English

SPF is a published list of the services allowed to send email for your domain: Google Workspace or Microsoft 365, say, plus your newsletter tool and any booking system that emails your customers. A receiving server checks whether a message came from somewhere on the list.

DKIM is a digital signature added to every message you send. It proves the email really came from your domain and was not altered on the way. Your email provider creates it; you publish the matching key.

DMARC is the instruction that ties the two together. It tells receiving servers what to do when a message claiming to be from you fails the checks — let it through, put it in spam or reject it — and where to send reports of who is using your name.

Why "we have SPF" is not enough

SPF and DKIM on their own only describe. DMARC is what makes receivers act. A DMARC policy of p=none is a sensible first step because it collects reports without blocking anything, but forged email is still delivered while it stays there. Protection starts at p=quarantine and is complete at p=reject.

There is a practical reason too. Since February 2024 Gmail and Yahoo have required SPF, DKIM and DMARC from anyone sending email in bulk. Messages from domains without them are more likely to land in spam. Getting this right protects your reputation and your own email at the same time.

How to check yours

Our free instant check tells you in a few seconds whether email from your domain can be forged. The full free website audit goes further: it reads each record, explains what it covers and what it misses and lists what to change, in order.

Fixing it without losing genuine email

The order matters. Start with SPF and DKIM covering every service that legitimately sends for you, then publish DMARC at p=none with reporting switched on. Read the reports for a week or two to confirm your own email passes. It is easy to forget the accounting package that sends invoices or the website form that emails enquiries. Then move to quarantine and eventually reject. Rushing straight to reject is how genuine invoices and quotes quietly disappear.

We did exactly this on our own domain: reports at p=none from early September 2026, quarantine for a quarter of failing mail from the middle of the month, then all of it in October once eleven days of reports showed every genuine message passing.

If you would rather not do it yourself, it is a small piece of work for us. Book a call or start with the free audit.

Find out what your business is actually spending.

Two days and a plain-English report you own outright.

Support