Is My Business Email Spoofable? A Plain-English Guide to SPF, DKIM and DMARC
If your domain is missing three small DNS records, a stranger can send invoices and password requests that look exactly like they came from you, and your customers may never know.
By Nathan Cross, Co-Founder, Network & Security Engineering·
What email spoofing actually is
"Is my business email spoofable?" is a question more owners should ask, because email was invented before anyone worried about fraud. By default the "From" address on a message is just a label the sender types in. Nothing in the basic system stops a scammer from writing your company name and your real email address in that box. The message can then land in your customer's inbox looking, to them, exactly like it came from you.
That is spoofing: forging the sender so a message appears to come from a domain it never touched. It is the engine behind a lot of small-business fraud, from fake invoices that change the bank account number, to "the owner needs gift cards urgently" messages aimed at your staff, to password-reset emails designed to phish your clients.
The good news is that the email world fixed this gap years ago. The fix is three small records you publish in your domain's DNS settings, and they tell the rest of the internet which servers are genuinely allowed to send mail as you. The bad news is that a great many small-business domains still have them missing, incomplete, or set to do nothing.
The three records that protect you: SPF, DKIM and DMARC
These three work as a team. Each is a TXT record published in your domain's DNS, and together they let a receiving mail server answer one question: was this message really authorised by the domain it claims to be from? (Cloudflare)
- SPF (Sender Policy Framework) is a public list of the mail servers allowed to send email for your domain. When a message arrives, the receiver checks whether it came from a server on your list.
- DKIM (DomainKeys Identified Mail) adds a tamper-proof digital signature to each message. The receiver uses a key you publish in DNS to confirm the message genuinely came from your domain and was not altered in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the first two together. It tells receiving servers what to do when a message fails SPF and DKIM, and it can send you reports showing who is sending mail in your name. (Cloudflare)
The setting that decides everything: p=none vs p=reject
DMARC is only as strong as its policy, and this is where most businesses quietly fall short. The policy is a single instruction in the record, written as a "p=" value, and it tells the world how seriously to take a failed check.
With p=none, you are in monitor-only mode. Receivers still check your mail and can send you reports, but they are told to deliver spoofed messages anyway. It is a useful first step while you confirm your own legitimate mail is set up correctly, but on its own it stops nothing. A domain sitting at p=none for months is, for practical purposes, still spoofable.
With p=quarantine, failing messages are sent to the spam folder. With p=reject, they are refused outright and never reach the inbox. Reject is the goal: it is the setting that actually blocks a forger from impersonating you. The safe path is to start at none, read the reports, fix anything legitimate that fails, then move up to quarantine and finally to reject.
How to check if my business email is spoofable right now
You do not need to be technical to find out. Anyone can look up the public DNS records for a domain, and that is exactly what a passive external scan does. The two things you are checking for are whether the records exist at all, and whether DMARC is doing anything stronger than p=none.
BadgerScan's free external check does this for you in seconds. Enter your domain and it reads your SPF, DKIM and DMARC records the same way a receiving mail server would, then tells you in plain English whether a stranger could send email as your business. It also checks the rest of your public security posture: your TLS certificate, your HTTP security headers, exposed files, and known vulnerabilities for software it can detect from the outside. The check is passive: it only reads what is already public and never tries to break in.
If you would rather read the raw records yourself, look for a TXT record starting with "v=spf1" on your main domain, a DKIM record on a selector your mail provider gives you, and a TXT record starting with "v=DMARC1" on the special _dmarc subdomain. The DMARC record is the one to read closely, because its p= value is what tells you whether you are protected or merely watching.
How to fix it
Fixing email authentication means editing DNS records, usually wherever your domain is registered or wherever your DNS is hosted. Most mainstream mail providers, including Microsoft 365 and Google Workspace, publish step-by-step instructions for the exact SPF and DKIM values to use, because the values depend on who sends your mail.
A sensible order of operations is: publish a correct SPF record listing every service that legitimately sends mail as you, enable DKIM signing in your mail provider and publish the key it gives you, then add a DMARC record starting at p=none with a reporting address. Watch the reports for a couple of weeks, make sure your real mail, including newsletters and invoicing tools, passes, then tighten the policy to quarantine and finally to reject.
The one mistake worth avoiding is leaving DMARC at p=none and assuming the job is done. Monitoring is not protecting. If you are not comfortable making these changes, or you want someone to confirm your real mail will not break when you tighten the policy, this is a common job for our team. We will get you to a genuine p=reject without losing a single legitimate email.
Why this matters more for a small business
It is tempting to assume attackers chase only big targets, but the data points the other way. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organisations (Verizon 2025 DBIR). Smaller firms are squarely in the crosshairs, and a spoofable domain is one of the easiest doors to walk through.
Email spoofing is also uniquely damaging because the harm often lands on the people who trust you most: your customers and suppliers. A forged invoice in your name does not just cost someone money, it costs your reputation. Closing the gap with SPF, DKIM and a real DMARC policy is one of the highest-value, lowest-cost security wins available to a small business, and it takes far less time than recovering from the fraud it prevents.
Find out in seconds whether someone can spoof your email
Run BadgerScan's free external check on your domain and see whether your SPF, DKIM and DMARC records actually protect you, or just look like they do. If you would like our Hamilton-based team to fix it and get you to a true p=reject without breaking your legitimate mail, we are a phone call away at (289) 796-8900.
Run a free security scanFrequently asked questions
Will turning on DMARC at p=reject block my own emails?
It can, if your legitimate mail is not set up to pass SPF and DKIM first. That is exactly why you start at p=none and read the reports: they show every service sending mail in your name. Once your real mail, including any newsletter or invoicing tools, passes cleanly, you can safely move to quarantine and then reject without losing legitimate messages.
I already have an SPF record. Am I protected?
Not fully. SPF alone tells receivers which servers may send your mail, but it does not tell them what to do when a check fails, and it does not cover the way some spoofing is done. You need DKIM signing as well, and a DMARC policy set to quarantine or reject, for the three to actually block a forger. A quick external scan will show which pieces you are missing.
How can I check if my business email is spoofable without being technical?
Run a free external scan. BadgerScan reads your domain's public SPF, DKIM and DMARC records the same way a receiving mail server does and tells you in plain English whether a stranger could send email as your business. You only need your domain name, and there is nothing to install.
Does fixing this require changing my email provider?
No. You keep your existing email. The changes are made in your domain's DNS records, not in your mailbox, and they tell the world which providers are allowed to send as you. If you use Microsoft 365 or Google Workspace, both publish the exact values to add.