The short answer: sending an e-mail that looks as if it comes from someone@asuaempresa.ao is trivial: the sender address is written freely, like the return address on a letter. To stop that there are three records in the domain’s DNS: SPF, DKIM and DMARC. The first two prove who may send; the third tells the world what to do with messages that fail. Without DMARC, the other two are only information.
What each one does
| Record |
The question it answers |
How it works |
| SPF |
“Is this server allowed to send for this domain?” |
A list, in DNS, of the authorised servers. |
| DKIM |
“Was the message really sent by who it says, and not altered?” |
A digital signature on every message, checked against a public key in DNS. |
| DMARC |
“What if a message fails both?” |
The domain owner’s policy: do nothing (none), quarantine (quarantine) or reject (reject), and where to send reports. |
All three records live in the domain’s DNS. If your domain uses Interweb’s nameservers, you edit them in the cPanel DNS zone editor; if it uses others, it is wherever the DNS is managed. Without access to the zone there is no SPF, DKIM or DMARC, so it is worth knowing now where it is.
How to tell whether someone is using your name
| 1 |
Signs from outside. Customers receiving e-mails you did not send, bounces for messages that never left you, or spam complaints in your name.
|
|
How to close the door, in stages
| 2 |
Publish DMARC in none mode. It blocks nothing; it just gives you the reports. Let it run for a while and confirm that your legitimate messages (from the site, the shop, the newsletter) pass.
|
|
| 3 |
Move up to quarantine, and later to reject, once your legitimate sources are all authorised. From then on, anyone forging your domain sees the messages rejected by the servers that respect DMARC.
|
|
Going straight to reject without reading the reports is the quickest way to lose legitimate e-mail. The invoicing system, the online shop or the newsletter service also send in the name of your domain. If they are not authorised in SPF or signed with DKIM, DMARC rejects them as if they were fake.
|
|
DMARC protects your exact domain. It does not stop someone registering a similar domain (with one letter swapped) and sending from there. Against that, only recipients’ attention helps: see how to recognise phishing.
|
|
Suspect your domain is being used to send e-mail? Send us an example with the full header.
Open a support ticket
|
RECOMMENDED PRODUCT Register your .ao domain Secure your company name before someone else registers it. from 30.000,00 Kz/yr Search a domain |