How to stop your domain being spoofed
How-to

How to stop your domain being spoofed

Stop domain spoofing by setting up SPF, DKIM and DMARC in your DNS, so mailbox providers can reject fake email sent in your name. The fix is free.

A1 Digital A1 Digital · written & reviewed by the team 4 min read Updated 3 July 2026

Quick answer

Domain spoofing is stopped by publishing three email authentication records, SPF, DKIM and DMARC, in your domain's DNS, so mailbox providers can verify genuine messages from you and reject any forged email sent in your name. Done right, the fixes are free, permanent and invisible to your customers.

3 records

SPF, DKIM and DMARC are all you need to stop exact-domain spoofing

£0

to set up email authentication, the records are free to publish in DNS

none → reject

the safe DMARC path: monitor first, then block the fakes

The nasty thing about spoofing is that your account never gets touched, so you’ve no idea it’s happening. A scammer sends an invoice “from” your business, with your name in the from-field, asking a customer to pay into a different bank account. The customer pays. The first you hear of it is an angry phone call. Your mailbox was never hacked; your name was simply borrowed, and the fix for that is free and lives entirely in your DNS.

To stop your domain being spoofed, set up three email authentication records, SPF, DKIM and DMARC, on your domain’s DNS, so mailbox providers can verify that messages claiming to come from you are genuine and reject the ones that aren’t. Done right, the fixes are free, permanent, and invisible to your customers. As a bonus, the same records help your real email land in the inbox.

The three records that do the work

These live in your domain’s DNS, the same place your website and email are pointed:

  • SPF (Sender Policy Framework) lists which servers are allowed to send email for your domain. Anything else looks suspicious.
  • DKIM (DomainKeys Identified Mail) adds a tamper-proof digital signature to every message, proving it really came from you and wasn’t altered.
  • DMARC (Domain-based Message Authentication) ties the two together and tells receiving servers what to do with mail that fails: nothing, quarantine it, or reject it outright.

The one-line version

SPF says who can send, DKIM proves it was really you, and DMARC decides what happens to the fakes. You need all three, not one or two.

How to set it up, step by step

1

Publish an SPF record

Add a single TXT record listing your email provider. Google Workspace uses v=spf1 include:_spf.google.com ~all; Microsoft 365 uses include:spf.protection.outlook.com. Only ever have ONE SPF record.

2

Turn on DKIM in your email provider

In Google Workspace or Microsoft 365 admin, generate the DKIM key, then paste the record it gives you into DNS. Switch DKIM signing on once the record's live.

3

Start DMARC in monitoring mode

Add a TXT record at _dmarc.yourdomain with v=DMARC1; p=none; rua=mailto:you@yourdomain. This watches and reports without blocking anything yet.

4

Read the reports, then tighten

After a few weeks, once the reports confirm all your genuine mail passes, move the policy to p=quarantine and finally p=reject to actively block spoofed mail.

Don't jump straight to reject

Setting DMARC to p=reject before checking the reports can block your own legitimate email, including newsletters, booking tools and invoicing apps. Always start at p=none and tighten gradually. Patience here saves a nasty surprise.

What these records can and can’t stop

DMARC protects your exact domain. It doesn’t stop a scammer registering a lookalike (your-business-ltd.com instead of yourbusiness.com) and sending from that.

Threat Stopped by SPF/DKIM/DMARC? What else helps
Exact-domain spoofing Yes, at p=reject Nothing more needed
Lookalike domains No Register close variants; staff training
Display-name spoofing Partly Staff awareness; verify payment changes by phone
Hacked mailbox No Strong passwords; two-factor login

For the lookalike and display-name cases, the cheapest defence is a simple rule everyone in the business follows: never act on a change of bank details or an urgent payment request from email alone. Confirm it by phone, using a number you already hold.

Why this also helps your real email

The same records that block fakes tell Gmail, Outlook and the rest that your genuine mail is trustworthy. Domains with proper authentication see fewer messages dropped into spam. If your invoices and replies keep vanishing, weak authentication is a common cause, see why emails land in spam.

Key takeaway

Spoofing protection is free and lives entirely in your DNS. Set SPF and DKIM, then ramp DMARC from monitoring to reject. The bonus is better inbox delivery for the email you actually want sent.

This is fiddly to get exactly right, and one typo in a DNS record can quietly break your email for everyone. We configure SPF, DKIM and DMARC for every client on a done-for-you plan and monitor the DMARC reports, so spoofing is shut down without your real mail getting caught in the crossfire. Rather have it handled? Get in touch.

Check it once a year

Ask whoever runs your email to confirm your DMARC policy is still at p=reject. Providers and tools change, and a record that’s quietly slipped back to p=none is doing nothing at all.

Check your domain today: search for a free DMARC checker, type in your domain, and see whether your business is already protected, or wide open to anyone who fancies wearing your name.

Frequently asked questions

What does it mean when my domain is spoofed?

Spoofing is when a scammer sends email that appears to come from your address, or a very similar one, without ever touching your account. They forge the 'from' field to trick your customers or staff into trusting the message, often to request payments or steal information. Your mailbox isn't hacked; your name is being borrowed.

Can I completely stop anyone pretending to be my business?

You can fully stop spoofing of your exact domain by setting SPF, DKIM and a DMARC policy of p=reject. You can't stop someone registering a lookalike domain or faking just the display name, so combine the technical fixes with a simple rule: verify any payment or bank-detail change by phone, never from email alone.

Will setting up DMARC break my own emails?

Not if you do it in the right order. Start DMARC at p=none, which only monitors and reports without blocking anything. Read those reports for a few weeks to confirm all your genuine mail passes SPF and DKIM, then tighten to quarantine and finally reject. Jumping straight to reject is what blocks legitimate email.

Do I need a developer for this?

Not necessarily, but you need access to your domain's DNS and your email provider's admin settings. The records are short pieces of text, but a single typo can silently break your email, so many small businesses prefer to have it configured and monitored for them. We handle this as standard for clients.

email domain security dmarc spf deliverability
Share Link copied
A1 Digital

Written by the A1 Digital team

We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.