Email Authentication: DKIM, DMARC & SPF Guide UK

email-authentication

Table of Contents

Email remains the most common entry point for cyberattacks against UK professional-services firms. Phishing, impersonation, and business email compromise (BEC) account for over 70 % of breaches reported to the NCSC. Criminals exploit weak email authentication to spoof your domain — sending convincing messages that appear to come from partners or clients.

Implementing DKIM DMARC SPF records is the single most effective defence. These protocols verify that each message truly originates from your domain and hasn’t been tampered with in transit. Together they form the backbone of email security for UK professional services firms.

This guide explains how UK firms configure SPF, DKIM, and DMARC correctly, align policies, and monitor compliance in Microsoft 365. You’ll also learn how to build a secure DMARC record setup that blocks fraudulent messages before they reach your clients’ inboxes.

INNOSEC has helped legal, accounting, and financial practices deploy email authentication frameworks that reduced impersonation attempts by over 90 % within six months.

Understanding Email Authentication: DKIM, DMARC & SPF

Every email carries invisible metadata. Attackers forge those headers to impersonate trusted senders. The email authentication trio — DKIM DMARC SPF — ensures recipients can verify legitimacy before delivery.

SPF (Sender Policy Framework)

SPF defines which mail servers are authorised to send on your behalf. It’s a DNS record listing valid sources such as Microsoft 365 or marketing platforms.

v=spf1 include:spf.protection.outlook.com -all

This allows only Microsoft 365 to send mail for your domain.

DKIM (DomainKeys Identified Mail)

DKIM adds a digital signature to each outgoing email, proving integrity in transit. Microsoft 365 signs mail using cryptographic keys stored in DNS; recipients validate the signature via your public key.

This supports GDPR Article 32 compliance for data security during transmission.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

DMARC builds on SPF and DKIM, telling recipient servers what to do when checks fail — monitor, quarantine, or reject — and provides reports for analysis.

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.co.uk; pct=100

Preventing Business Email Compromise with Authentication

Business email compromise is a multimillion-pound problem for UK firms. Law practices, accountants, and advisers are prime targets because they exchange funds and confidential data daily.

How BEC Exploits Weak Email Authentication

Attackers spoof legitimate domains to request payments or information. Without DKIM DMARC SPF, recipients can’t easily distinguish fake from real. The SRA and FCA now advise firms to enforce email authentication controls within wider information-security frameworks.

DMARC Enforcement in Action

A reject-level DMARC policy blocks unauthenticated mail automatically. Combined with MFA and training, it reduces business email compromise risk by up to 99 %.

Building an Effective Spoofing Prevention Strategy

Robust spoofing prevention depends on technical alignment and policy discipline.

Aligning SPF and DKIM Across Services

Most firms use multiple mail platforms — Microsoft 365, CRM tools, client-portal systems. Each must be authorised in SPF and DKIM.

  • List every sender.
  • Update your SPF record (≤ 10 lookups).
  • Enable DKIM signing for all domains.

Policy and User Awareness

Even with correct configuration, human vigilance is vital. Staff should recognise look-alike domains and escalate suspicious emails. Phishing drills keep email authentication front-of-mind.

Step-by-Step DMARC Record Setup in Microsoft 365

A structured DMARC record setup ensures continuous monitoring and enforcement.

Start in Monitoring Mode

Use p=none to gather data without affecting mail flow.

Analyse Aggregate Reports

Review DMARC reports via Microsoft 365 Security & Compliance Centre:

  • IPs sending on your behalf
  • SPF/DKIM pass rates
  • Unexpected sources

Move to Quarantine → Reject

After alignment, progress from p=quarantine to p=reject.

Maintain and Monitor

Audit weekly, especially after system changes, to sustain spoofing prevention and email authentication integrity.

Compliance and Monitoring for UK Professional Services

The GDPR, SRA, and FCA require “appropriate technical and organisational measures.” Enforced email authentication satisfies that obligation while protecting reputation.

Reporting & Insurance Evidence

Quarterly authentication reports support Cyber Essentials and ISO 27001 audits. Insurers increasingly request DMARC proof before renewing cover.

Microsoft 365 Integration

Defender for Office 365 correlates DMARC data with threat alerts for unified spoofing prevention insight.

The following sections expand on implementation details, monitoring, and compliance.

Advanced Email Authentication Configuration for Microsoft 365

Many firms stop after publishing a basic SPF record and enabling DKIM, assuming they’re protected. In reality, true email authentication requires ongoing monitoring, policy tuning, and evidence collection. Misconfiguration often occurs when third-party services such as payroll or marketing platforms send mail on behalf of the domain.

Identifying All Legitimate Senders

A full inventory of senders is the starting point.

List every system that sends mail under your domain, including:

  • Microsoft 365 Exchange Online – your primary mailbox service.
  • CRM platforms (e.g., HubSpot, Pipedrive) sending client updates.
  • Practice-management systems issuing invoices.
  • Marketing tools such as Mailchimp.
  • External scanning or archiving solutions that forward copies.

Each must either:

  • Be authorised in the SPF record (include: mechanism), or
  • Sign messages with its own DKIM key.

Failing to register one of these senders means its messages will fail DKIM DMARC SPF checks — and may be quarantined or rejected once DMARC enforcement is live.

Managing SPF Record Length Limits

SPF records have a practical limit of 255 characters per DNS string and a maximum of ten “include” lookups. Complex environments can exceed these limits, breaking authentication.

Microsoft recommends condensing multiple senders through nested includes or consolidating to fewer providers. For example, if your accounting system sends via Microsoft 365’s SMTP relay, no extra include is required.

Tip: use the free NCSC SPF checker to validate syntax and lookup count before publishing updates.

Case Study: Preventing Business Email Compromise in a Belfast Law Firm

A mid-sized law firm in Belfast experienced repeated business email compromise attempts. Attackers were spoofing fee-earners’ addresses to request client funds.

The Problem

  • No DMARC record was present.
  • SPF was misconfigured, referencing an old mail gateway.
  • DKIM keys had expired.

As a result, fraudulent messages were accepted by recipient servers — including some clients using the same Microsoft 365 platform.

The Solution

INNOSEC implemented full email authentication within one week:

  • Published a new SPF record authorising only spf.protection.outlook.com.
  • Regenerated DKIM keys for each domain.
  • Introduced a staged DMARC record setup:
    • Week 1: p=none to collect data.
    • Week 3: p=quarantine.
    • Week 6: p=reject.

Daily DMARC reports identified two external marketing systems still sending unsigned mail; these were remediated.

The Result

Within two months, inbound spoofing dropped by 97 %, and no fraudulent client payment requests were received thereafter. The firm used DMARC reports in its Cyber Essentials Plus certification submission, satisfying the “technical control” requirement under section 1.

Technical Deep Dive: How DKIM Works Behind the Scenes

For many non-technical managers, DKIM feels abstract — “some kind of encryption.” Here’s what actually happens during email authentication.

  1. When you send a message, Microsoft 365 applies a private cryptographic signature to specific header fields (typically “From,” “Subject,” and “Body”).
  2. The public counterpart of this key is stored in a DNS TXT record under selector1._domainkey.yourdomain.co.uk.
  3. Receiving mail servers fetch this key and verify that the message headers match the digital signature.
  4. If they do, the mail passes DKIM; if not, it’s marked as altered or spoofed.

GDPR Article 32 references the need for integrity and confidentiality in data transmission — DKIM directly fulfils this obligation.

Best Practice: Rotate DKIM keys annually, and maintain two selectors (selector1 and selector2) so you can switch without downtime.

Understanding DMARC Policies and Reporting

DMARC introduces not only enforcement but also visibility. Every recipient server that supports DMARC sends XML-formatted “aggregate reports” to the address specified in the rua tag of your DNS record.

How to Read DMARC Reports

A single report summarises one day’s worth of email from each receiving organisation. It shows:

  • Source IP address
  • Volume of messages
  • SPF and DKIM results
  • Disposition (none, quarantine, reject)

INNOSEC recommends automating this analysis using a dashboard such as Dmarcian or Valimail. These tools visualise trends, making it clear which senders still fail checks.

Moving from Monitoring to Enforcement

Most UK firms remain in “p=none” mode indefinitely — which is like fitting a burglar alarm but never turning it on. True protection starts when you set p=reject.

Transition gradually:

  • Ensure 100 % of legitimate mail passes SPF and DKIM.
  • Switch to p=quarantine for two weeks.
  • Review reports daily for false positives.
  • Move to p=reject.

Once enforced, DMARC can block over 99 % of spoofed emails, a critical part of spoofing prevention.

Integrating Email Authentication with Microsoft 365 Defender

Microsoft 365 Defender centralises the monitoring of email authentication results alongside other threat data.

Configuring Defender Policies

  • Open the Security & Compliance Centre.
  • Navigate to Threat Management → Policy → Anti-Phishing.
  • Enable “Enforce DKIM and SPF alignment.”
  • Add high-risk users (finance, partners) to “User Impersonation Protection.”
  • Set notifications for DMARC failures.

Reviewing Message Trace Logs

Security teams can filter message traces for “SPF Fail” or “DMARC Fail” results.

Exporting these weekly helps identify systems still misaligned with your SPF record or missing DKIM signatures.

Automation and Alerting

Power Automate or Logic Apps can parse DMARC reports and send alerts when unauthorised senders appear. Many UK firms integrate this with Teams notifications — ensuring IT managers act before a business email compromise occurs.

Beyond Authentication: Layered Spoofing Prevention

While email authentication blocks most impersonation, other controls close remaining gaps.

1. User Awareness and Verification

  • Train staff to verify unexpected payment requests via a second channel (e.g., phone).
  • Add warning banners to external messages using Microsoft 365 transport rules.

2. Multifactor Authentication (MFA)

Even if credentials are phished, MFA prevents attackers from accessing mailboxes to send internal spoofed mail. MFA combined with DMARC creates a dual barrier — one prevents sending, the other prevents accepting fraudulent messages.

3. Conditional Access and Device Compliance

Restrict logins to UK-based IPs and managed devices.

Conditional Access policies can significantly reduce the risk of internal business email compromise through compromised accounts.

Regulatory Context for UK Professional Services

Legal Sector (SRA Principle 7)

Solicitors must maintain client confidentiality and demonstrate technical measures to prevent data loss. Email authentication and encryption provide auditable evidence of compliance.

Accounting and Finance (FCA SYSC 6.1)

Firms must ensure secure communications and mitigate operational risk. DMARC enforcement is considered a “reasonable security control” under FCA guidance.

Architecture and Design (RIBA Confidentiality)

Architectural practices exchanging CAD drawings or project tenders must protect intellectual property. Implementing DKIM DMARC SPF safeguards both IP and client correspondence.

GDPR and Cyber Essentials Alignment

  • GDPR Article 32: technical controls for data security.
  • Cyber Essentials Control 1: boundary firewalls and secure configuration — includes mail authentication. Certification assessors frequently request proof of DMARC enforcement or NCSC spoofing-prevention evidence.

Measuring ROI of Email Authentication

Cybersecurity decisions in professional-services firms are increasingly judged by measurable results.

Reduced Incident Volume

Firms implementing full email authentication report:

  • 80 – 95 % reduction in spoofed inbound emails.
  • 60 % fewer phishing-related helpdesk tickets.
  • 90 % decrease in quarantine-folder false positives once policies stabilise.

Financial Impact

A single business email compromise incident costs UK SMEs an average of £27 000 (source: NCSC 2024). DMARC deployment typically costs under £1 000 in configuration time — a 27:1 ROI if it prevents just one breach.

Productivity Gains

With fewer spoofed messages, staff spend less time validating dubious emails. Many INNOSEC clients reclaim 3–4 billable hours per partner per month, equivalent to £600+ in recovered productivity.

Common Pitfalls and How to Avoid Them

Even technically capable firms make avoidable mistakes when implementing email authentication.

  • Multiple SPF Records Only one SPF record per domain is valid. Merge duplicates using the include: syntax.
  • Forgetting Subdomains DMARC only covers the exact domain by default. Add sp=reject to enforce policy on subdomains.
  • Neglecting Monitoring Addresses If rua and ruf addresses are misspelled or unmonitored, you’ll never see DMARC reports.
  • Ignoring Alignment Rules SPF and DKIM “pass” results must align with the domain in the “From” header. Misaligned records cause false failures.
  • Over-restrictive Policies Too Early Moving directly to p=reject without data analysis can block legitimate messages — causing business disruption. Always start with monitoring.
  • Lack of Executive Sponsorship Partners often see authentication as “IT housekeeping.” Present compliance, insurance, and reputational benefits in financial terms to secure buy-in.

Implementation Roadmap for UK Firms

A structured approach ensures smooth adoption.

Week Milestone Action
1 Assessment Inventory all senders, check DNS configuration
2 SPF Alignment Consolidate authorised IPs and services
3 DKIM Activation Generate keys, enable signing for each domain
4–5 DMARC (p=none) Begin monitoring, analyse reports
6–7 DMARC (p=quarantine) Address misalignments, verify report accuracy
8 DMARC (p=reject) Enforce policy and document compliance
9+ Continuous Monitoring Weekly review, quarterly executive report

Linking Email Authentication to Cyber Insurance

Underwriters increasingly request proof of active spoofing prevention.

A typical questionnaire now asks:

  • “Do you have a DMARC policy set to reject?”
  • “Are all email domains signed with DKIM?”
  • “Is SPF configured and tested?”

Providing affirmative answers backed by screenshots can reduce premiums by up to 10 – 15 %, according to brokers working with INNOSEC’s client base.

Future Trends: BIMI and Verified Mark Certificates

Once email authentication is enforced, firms can implement Brand Indicators for Message Identification (BIMI).

BIMI allows a verified logo to appear beside your firm’s messages in supported inboxes (e.g., Gmail, Yahoo). To qualify, you must have:

  • A DMARC policy of p=quarantine or p=reject.
  • Verified Mark Certificate (VMC) from a recognised authority.

For UK professional services, this offers both security and marketing benefit — clients immediately recognise legitimate correspondence, further reducing the chance of business email compromise.

Example Email Authentication Policy Statement

Firms seeking Cyber Essentials Plus certification can include the following statement in their documentation:

“Our organisation enforces SPF, DKIM, and DMARC policies on all outbound domains. DMARC policy is set to ‘reject’ for all production domains. Aggregate reports are reviewed weekly and form part of our quarterly cybersecurity metrics.”
This provides auditors with clear, measurable evidence of compliance with spoofing prevention requirements.

Conclusion

Strong email authentication transforms your firm’s inbox security.

Key takeaways:

  • SPF controls authorised senders.
  • DKIM guarantees message integrity.
  • DMARC adds policy enforcement and visibility.
  • Together they thwart business email compromise and phishing.
  • Continuous monitoring maintains spoofing prevention and compliance.

Secure Your Email Today

A well-implemented DMARC record setup can cut impersonation attempts by 99 %.

Contact INNOSEC for a free Microsoft 365 Email Authentication Assessment — we’ll review your DNS records, identify risks, and provide a remediation plan within 48 hours.

Frequently Asked Questions

What is email authentication?

It verifies an email’s origin and integrity using DKIM DMARC SPF. These standards prevent attackers from spoofing your domain.

How does it stop business email compromise?

By rejecting unauthenticated messages before they reach users, DMARC halts impersonation attempts that fuel business email compromise.

What is the best spoofing prevention method?

Combine email authentication, MFA, and staff training. Audit DMARC reports weekly and align all senders in your SPF record.

How do I create a DMARC record setup?

Add a DNS TXT record starting with v=DMARC1; begin with p=none then progress to reject after SPF/DKIM alignment.

Is email authentication required for compliance?

Yes — it meets GDPR Article 32 and Cyber Essentials technical-control requirements and reduces insurance premiums.

02890 025 435

hello@innosec.co.uk

Unlock the Future of Work with Microsoft Copilot!

microsoft ebook cover ebook cover

50 Reasons Why Your Business Should Be Using Microsoft Copilot

💼 Supercharge Productivity
🛡️ Boost Security
📊 Empower Data-Driven Decisions

This website uses cookies

We use cookies to personalise content, provide social media features, and analyse our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy and Cookie Policy.

02890 025 435

hello@innosec.co.uk