AWSMTECH

Is Your Domain Really Protected Against Email Spoofing?

CybersecurityBy Editorial Team6 min read
Laptop in a dark office showing an email inbox, with one message authenticated by a lime green seal and a translucent copy drifting away

01Email Spoofing Remains a Surprisingly Common Problem

When a business invests in its digital presence, it generally protects its website, its Microsoft 365 access or its critical data.

The email domain often receives less attention.

Yet without specific protection mechanisms, a malicious actor can send a message using a company’s domain name in the sender field. The aim is not necessarily to compromise the technical infrastructure, but rather to exploit the credibility associated with the brand and its digital identity. [cloudflare.com], [knowledge....oadcom.com]

This technique is frequently used in phishing campaigns, CEO fraud and business email compromise attempts.

From the recipient’s point of view, the message sometimes appears to come from the legitimate organisation.

02Three Standards Have Emerged to Secure Email

To address this risk, the industry now relies on three complementary mechanisms.

SPF: Declaring Who Is Allowed to Send

The SPF (Sender Policy Framework) protocol allows an organisation to publish the list of servers authorised to send emails for its domain. When a message is received, the recipient server can check whether the sender is among the authorised sources. [knowledge....oadcom.com], [cloudflare.com]

In practice, SPF answers a simple question:

Is this server allowed to send messages on behalf of this domain?

DKIM: Guaranteeing Message Integrity

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing messages. This signature allows the recipient server to verify that the content of the message has not been altered between sending and receipt. [knowledge....oadcom.com], [cloudflare.com]

DKIM therefore does not only validate the sender’s identity.

It also confirms that the message received matches the one that was sent.

DMARC: Defining the Trust Policy

DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on SPF and DKIM.

The protocol allows the domain owner to tell mail servers what to do when a message fails the checks: accept it, quarantine it or reject it. [knowledge....oadcom.com], [cloudflare.com]

DMARC also provides valuable visibility through reports that show how the domain is being used and which sources are attempting to send messages on its behalf. [knowledge....oadcom.com]

03The Real Issue Is No Longer Adoption, but Configuration Maturity

For many Swiss SMEs, SPF, DKIM and DMARC are no longer unfamiliar concepts.

The problem lies elsewhere.

Many organisations do have these DNS records, but with limited policies.

For example, it is not unusual to see DMARC configured in monitoring mode (p=none), which makes it possible to observe spoofing attempts without asking recipient servers to block the messages concerned.

This approach is useful during deployment phases.

But when it becomes permanent, protection remains partial.

As several industry technical guides explain, the added value of DMARC mainly emerges when a quarantine or reject policy is gradually implemented after legitimate mail flows have been validated. [knowledge....oadcom.com], [easydmarc.com]

04SMEs Are Particularly Affected

The issue directly affects SMEs.

Unlike large enterprises, which sometimes have teams specialising in digital identity governance, SMEs often rely on external providers and accumulate services over time:

  • Microsoft 365;
  • marketing platform;
  • CRM;
  • invoicing tool;
  • newsletter sending solution;
  • HR portal.

Every platform that may send emails must be taken into account in the domain’s authentication policy.

This proliferation of services increases the risk of configuration errors.

It also explains why some businesses have an incomplete SPF record, a partially deployed DKIM or a DMARC policy that was never finalised.

05A Reputation Issue as Much as a Cybersecurity Issue

Email security is often presented as a purely technical subject.

Yet it has much broader implications.

A poorly protected domain can be used to send:

  • fake sales messages;
  • fake invoices;
  • fraudulent payment requests;
  • phishing campaigns targeting customers or partners.

Even when the business itself has not been directly compromised, its image can suffer.

Conversely, correctly implementing SPF, DKIM and DMARC also helps build trust with the major mailbox providers and improves the deliverability of legitimate messages. [powerdmarc.com], [cloudflare.com]

06The Digital Giants Are Tightening Requirements

Recent market developments point in the same direction.

Major mailbox providers are placing increasing importance on domain authentication. Technical guides published in 2026 point out in particular that SPF, DKIM and DMARC have become benchmark elements for demonstrating the legitimacy of a sending domain and combating spoofing. [linuxize.com], [cloudflare.com]

For businesses, the question is therefore no longer whether these mechanisms should be put in place.

It is rather about their level of maturity and their real effectiveness.

07A Simple Indicator of Digital Maturity

For an executive or IT manager, a few questions are already enough to assess the situation:

  • Is SPF configured for all the sending services in use?
  • Is DKIM active on Microsoft 365 and on third-party platforms?
  • Is DMARC deployed in monitoring mode or in protection mode?
  • Does the business receive and analyse DMARC reports?
  • Is there a periodic review of authorised services?

The answers to these questions are often a more relevant indicator than the mere presence of a DNS record.

08Behind SPF, DKIM and DMARC: A Question of Trust

Email authentication is not just an infrastructure matter.

It contributes to the digital trust an organisation maintains with its customers, suppliers and employees.

As impersonation attacks become more professional, the ability to prove that a message genuinely comes from a legitimate domain is becoming an essential part of that trust.

For Swiss SMEs, the question is therefore no longer really technical.

It has become strategic:

Does the business know today who can send emails on its behalf?

Box | Three Quick Checks

  • 1. Does your domain have a valid SPF record?
  • 2. Is DKIM enabled on all your message-sending services?
  • 3. Is your DMARC policy configured to reject spoofed messages, or only to monitor them?

09Sources

  • What are DMARC, DKIM, and SPF? (Cloudflare) [cloudflare.com]
  • How to prevent sender and domain spoofing using SPF, DKIM, DMARC (Broadcom) [knowledge....oadcom.com]
  • Email Authentication Explained: SPF, DKIM, and DMARC [linuxize.com]
  • DMARC, DKIM, SPF: Email Authentication Best Practices [easydmarc.com]

Do you know who can send emails on behalf of your domain?

AWSMTECH reviews your domain’s SPF, DKIM and DMARC configuration and guides you towards a protection policy suited to your sending services.

Talk to an expert