Module 4 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: how email spoofing powers invoice fraud, what SPF, DKIM, and DMARC each do in plain English, and the exact steps to set all three up for Microsoft 365.
Stop Email Spoofing: SPF, DKIM, and DMARC in Plain English
The scam: email that looks exactly like you
Here is how the classic invoice scam plays out. Your bookkeeper gets an email from you, or so it appears. Same display name, same email address, even your usual sign-off. It says a supplier has changed banks and the attached invoice should be paid to the new account. The money goes out on Friday. By the time anyone rings the real supplier, it is sitting in an account that no longer exists.
The uncomfortable part is how easy the impersonation is. Email was designed in a friendlier era, and by default nothing stops a scammer typing your domain into the From field of a message. It costs them nothing and it works often enough that this style of attack, known as business email compromise (or BEC), is one of the most expensive crimes going. Microsoft lists spoofed senders as a key ingredient in BEC, ransomware, and phishing campaigns.
The fix is three small DNS records with awkward names: SPF, DKIM, and DMARC. Together they let the receiving mail server check whether a message claiming to be from your domain actually is, and tell it what to do when the answer is no. None of them cost anything. All three are things you set up once and mostly leave alone.
There is a selfish reason to do this too. The big mail providers increasingly treat email from domains without these records as suspect, so your own quotes and invoices are more likely to land in spam. Set the three records up and you protect your customers from fake you, and your real mail from the junk folder. Two birds, three DNS records.