SOLVBEAT
HomeBlog › SPF, DKIM and DMARC explained: how to stop people spoofing your email

SPF, DKIM and DMARC explained: how to stop people spoofing your email

Published 2 August 2026 · Solvbeat
SPF, DKIM and DMARC explained: how to stop people spoofing your email

Anyone can send an email pretending to be you

Email doesn't verify who actually sent a message by default — it just trusts the "From" field. Without the right DNS records in place, someone can send an email that says it's from billing@yourcompany.co.uk and most inboxes will happily deliver it. This is the basis of the majority of targeted phishing against real businesses.

The three records that actually stop it

Why "I have SPF" usually isn't enough

The most common gap isn't a missing record — it's a DMARC policy set to p=none, which only monitors and reports, but doesn't actually block anything. It's a good first step, but on its own it won't stop a single spoofed email from landing in your customer's inbox.

Check your domain's SPF, DKIM and DMARC free →

See your website the way a hacker does.
Free scan — no login, no card — a clear report in under a minute.
Run a free scan →