How to stop your domain being spoofed
Stop domain spoofing by setting up SPF, DKIM and DMARC in your DNS, so mailbox providers can reject fake email sent in your name. The fix is free.
Quick answer
Domain spoofing is stopped by publishing three email authentication records, SPF, DKIM and DMARC, in your domain's DNS, so mailbox providers can verify genuine messages from you and reject any forged email sent in your name. Done right, the fixes are free, permanent and invisible to your customers.
3 records
SPF, DKIM and DMARC are all you need to stop exact-domain spoofing
£0
to set up email authentication, the records are free to publish in DNS
none → reject
the safe DMARC path: monitor first, then block the fakes
The nasty thing about spoofing is that your account never gets touched, so you’ve no idea it’s happening. A scammer sends an invoice “from” your business, with your name in the from-field, asking a customer to pay into a different bank account. The customer pays. The first you hear of it is an angry phone call. Your mailbox was never hacked; your name was simply borrowed, and the fix for that is free and lives entirely in your DNS.
To stop your domain being spoofed, set up three email authentication records, SPF, DKIM and DMARC, on your domain’s DNS, so mailbox providers can verify that messages claiming to come from you are genuine and reject the ones that aren’t. Done right, the fixes are free, permanent, and invisible to your customers. As a bonus, the same records help your real email land in the inbox.
The three records that do the work
These live in your domain’s DNS, the same place your website and email are pointed:
- SPF (Sender Policy Framework) lists which servers are allowed to send email for your domain. Anything else looks suspicious.
- DKIM (DomainKeys Identified Mail) adds a tamper-proof digital signature to every message, proving it really came from you and wasn’t altered.
- DMARC (Domain-based Message Authentication) ties the two together and tells receiving servers what to do with mail that fails: nothing, quarantine it, or reject it outright.
The one-line version
SPF says who can send, DKIM proves it was really you, and DMARC decides what happens to the fakes. You need all three, not one or two.
How to set it up, step by step
Publish an SPF record
Add a single TXT record listing your email provider. Google Workspace uses v=spf1 include:_spf.google.com ~all; Microsoft 365 uses include:spf.protection.outlook.com. Only ever have ONE SPF record.
Turn on DKIM in your email provider
In Google Workspace or Microsoft 365 admin, generate the DKIM key, then paste the record it gives you into DNS. Switch DKIM signing on once the record's live.
Start DMARC in monitoring mode
Add a TXT record at _dmarc.yourdomain with v=DMARC1; p=none; rua=mailto:you@yourdomain. This watches and reports without blocking anything yet.
Read the reports, then tighten
After a few weeks, once the reports confirm all your genuine mail passes, move the policy to p=quarantine and finally p=reject to actively block spoofed mail.
Don't jump straight to reject
Setting DMARC to p=reject before checking the reports can block your own legitimate email, including newsletters, booking tools and invoicing apps. Always start at p=none and tighten gradually. Patience here saves a nasty surprise.
What these records can and can’t stop
DMARC protects your exact domain. It doesn’t stop a scammer registering a lookalike (your-business-ltd.com instead of yourbusiness.com) and sending from that.
| Threat | Stopped by SPF/DKIM/DMARC? | What else helps |
|---|---|---|
| Exact-domain spoofing | Yes, at p=reject | Nothing more needed |
| Lookalike domains | No | Register close variants; staff training |
| Display-name spoofing | Partly | Staff awareness; verify payment changes by phone |
| Hacked mailbox | No | Strong passwords; two-factor login |
For the lookalike and display-name cases, the cheapest defence is a simple rule everyone in the business follows: never act on a change of bank details or an urgent payment request from email alone. Confirm it by phone, using a number you already hold.
Why this also helps your real email
The same records that block fakes tell Gmail, Outlook and the rest that your genuine mail is trustworthy. Domains with proper authentication see fewer messages dropped into spam. If your invoices and replies keep vanishing, weak authentication is a common cause, see why emails land in spam.
Key takeaway
Spoofing protection is free and lives entirely in your DNS. Set SPF and DKIM, then ramp DMARC from monitoring to reject. The bonus is better inbox delivery for the email you actually want sent.
This is fiddly to get exactly right, and one typo in a DNS record can quietly break your email for everyone. We configure SPF, DKIM and DMARC for every client on a done-for-you plan and monitor the DMARC reports, so spoofing is shut down without your real mail getting caught in the crossfire. Rather have it handled? Get in touch.
Check it once a year
Ask whoever runs your email to confirm your DMARC policy is still at p=reject. Providers and tools change, and a record that’s quietly slipped back to p=none is doing nothing at all.
Check your domain today: search for a free DMARC checker, type in your domain, and see whether your business is already protected, or wide open to anyone who fancies wearing your name.
Frequently asked questions
What does it mean when my domain is spoofed?
Spoofing is when a scammer sends email that appears to come from your address, or a very similar one, without ever touching your account. They forge the 'from' field to trick your customers or staff into trusting the message, often to request payments or steal information. Your mailbox isn't hacked; your name is being borrowed.
Can I completely stop anyone pretending to be my business?
You can fully stop spoofing of your exact domain by setting SPF, DKIM and a DMARC policy of p=reject. You can't stop someone registering a lookalike domain or faking just the display name, so combine the technical fixes with a simple rule: verify any payment or bank-detail change by phone, never from email alone.
Will setting up DMARC break my own emails?
Not if you do it in the right order. Start DMARC at p=none, which only monitors and reports without blocking anything. Read those reports for a few weeks to confirm all your genuine mail passes SPF and DKIM, then tighten to quarantine and finally reject. Jumping straight to reject is what blocks legitimate email.
Do I need a developer for this?
Not necessarily, but you need access to your domain's DNS and your email provider's admin settings. The records are short pieces of text, but a single typo can silently break your email, so many small businesses prefer to have it configured and monitored for them. We handle this as standard for clients.
Written by the A1 Digital team
We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.
On this page
Keep reading
What are SPF, DKIM and DMARC (in plain English)?
SPF, DKIM and DMARC are three DNS records that prove your emails are genuine, so they reach inboxes instead of spam and stop scammers spoofing your domain.
GuideWhy your emails land in spam (and how to fix it)
Emails land in spam from missing SPF/DKIM/DMARC, sending via free Gmail, and poor habits. Fix all three and the inbox stops being a guessing game.
How-toHow to set up email at your own domain
Set up email at your own domain: pick a host (Google Workspace or Microsoft 365), add your domain, create addresses, then add the DNS records.