If someone wanted to impersonate your business, they probably could.
They wouldn’t need to hack your systems.
They wouldn’t need access to your email account.
They could simply send an email pretending to be you.
And to the person receiving it, it could look completely legitimate.
That’s the real problem SPF, DKIM and DMARC are designed to solve.

Start With the Real Risk
Most email fraud doesn’t look suspicious.
It looks:
- Familiar
- Normal
- Often urgent
In many cases, it appears to come from a genuine address.
That’s because this isn’t always about hacking.
It’s about impersonation, timing, and pressure.
A Simple Example
Someone registers:
aff1rmit.co.uk instead of affirmit.co.uk
They send an email to your accounts team asking for a payment.
The name looks right.
The signature looks right.
The wording feels normal.
Most people won’t spot the difference straight away.
That’s how this works.

SPF – Where Your Email Is Allowed to Come From
SPF is the simplest piece.
Think of it as a list of approved senders.
It tells receiving systems:
“These are the systems allowed to send email for this domain.”
If an email comes from somewhere else, it can be flagged or blocked.
DKIM – Proving the Email Hasn’t Been Changed
DKIM adds a signature to every email.
When the message is received, that signature is checked.
If anything has been altered, the check fails.
That tells the receiving system something is wrong.
DMARC – Deciding What Happens Next
DMARC brings everything together.
It tells the receiving system what to do if something doesn’t pass:
- Reject it
- Quarantine it
- Or just monitor
In simple terms:
DMARC decides what happens next
SPF checks where it came from
DKIM checks it hasn’t been altered

Why This Gets Missed
One of the most common beliefs is:
“We’ve got email, so we’re secure.”
That’s not the case.
Most email systems will happily send and receive messages without checking whether they’re genuine.
That’s where the gap is.
This Isn’t About Staff
Fraud works because people are:
- Busy
- Helpful
- Trying to do the right thing
The solution isn’t asking people to be more suspicious.
It’s putting systems in place so those emails don’t get through in the first place.
Where These Controls Sit
These aren’t advanced tools.
They’re basic protection for your domain.
They sit in the background and filter emails before your team ever sees them.
Quick Comparison
| Control | What It Does |
|---|---|
| SPF | Checks where the email was sent from |
| DKIM | Checks it hasn’t been changed |
| DMARC | Controls what happens if it fails |

How Do You Know If Yours Are Set Up?
Most businesses don’t.
It’s common to find:
- No SPF record at all
- DKIM not turned on
- DMARC set to monitoring only
Microsoft 365 supports all of this, but it still has to be set up properly.
Until it is, you’re relying on people spotting issues manually.
Final Thoughts
Email is where a lot of fraud starts.
If your domain can be impersonated, everything else becomes harder to protect.
SPF, DKIM and DMARC don’t stop every attack.
But they remove a large part of the risk before it reaches your team.

FAQ
Can someone send emails pretending to be my business?
Yes. Without these controls, it’s relatively easy to do.
Do small businesses need this?
Yes. Impersonation affects businesses of all sizes.
Does Microsoft 365 include this automatically?
It supports it, but it still needs to be configured.
Will it stop all phishing?
No. But it reduces a significant amount of impersonation.
What’s the difference between SPF, DKIM and DMARC?
SPF checks the sender, DKIM checks the message, DMARC decides what happens.
Need Help?
At Affirm IT, we start with simple questions:
- Can your domain be used to send emails by anyone else?
- What happens if an email fails checks?
- Are you relying on your team to spot problems?
From there, we put the basics in place properly.
If you’re not sure where you stand, get in touch., get in touch with us. At Affirm IT, we specialise in providing comprehensive IT support for small businesses in Heanor, Ripley, Ilkeston, Eastwood and all over the UK
