Secure business email: SPF, DKIM, DMARC and encryption
The technologies that protect business email from spoofing and interception: what SPF, DKIM, DMARC and TLS are, and why they are essential today.

Email remains the most widely used work tool and, for that very reason, the favorite way in for anyone who wants to attack a company. Two risks are particularly insidious: someone impersonating your company by writing to your customers, and messages that travel in clear text and can be read along the way.
There are standard, free technologies that greatly reduce both risks. The problem is that they are often not configured, or only partially.
SPF: who can send on your behalf
SPF (Sender Policy Framework) is a record published in the domain’s DNS that lists the servers authorized to send email on behalf of the company. The receiving server checks whether a message comes from one of those servers.
Be sure to include every service that sends on your behalf: your business email, but also your ERP, your CRM and your newsletter platform.
DKIM: the message’s digital signature
With DKIM (DomainKeys Identified Mail), the sending server signs every message with a private key. The matching public key is published in DNS: the recipient uses it to verify that the signature is genuine and that the content has not been altered along the way.
DMARC: what to do with fake messages
DMARC brings SPF and DKIM together and tells receiving servers how to handle messages that fail the checks: deliver them anyway and report them, quarantine them or reject them. It also lets you receive periodic reports on who is sending email using your domain.
The recommended path is gradual: start with a monitoring-only policy, analyze the reports, fix the configurations and move on to quarantine and then rejection.
It is no longer optional: since 2024 major email providers such as Google and Yahoo require SPF, DKIM and DMARC from bulk senders, and generally reward properly configured domains.
TLS: encryption in transit
The TLS protocol encrypts the connection between mail servers, so messages do not travel in clear text. It is very widespread today, but often only “opportunistic”: if the server at the other end does not support it, the message is sent anyway without encryption. For communications with important partners and customers, you can enforce TLS.
When you need more: message encryption
For contracts, health data, financial or legal information you may need a further level: encryption of the message itself, which stays protected even after it reaches its destination and can be read only by the authorized recipient.
A quick checklist
- Does your domain have a complete, up-to-date SPF record?
- Do all the services that send on your behalf sign with DKIM?
- Is DMARC published, and does someone read the reports?
- Is your email protected by filters against phishing, malware and dangerous links?
- Is there an easy-to-use encryption solution for confidential messages?
How we help
With EagleMercury, business email is protected by advanced filters against spam, phishing and malware, with archiving and tools for secure document exchange. Our technicians configure SPF, DKIM and DMARC for your domains and guide you, report after report, all the way to full protection.


