Guidance
Email security and anti-spoofing
A guide for IT managers and systems administrators
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 10 of 14
Advice for when you have set up a DMARC policy of 'none', including monitoring your reports for at least two weeks and correcting any failures.
Implementing a DMARC policy of 'none' on your domains won’t affect the delivery of your email but neither will it prevent illegitimate emails being sent from your domains. For this, you must at least implement a DMARC policy of ‘quarantine’.
Before you do this, you must ensure that you have correctly configured DMARC and SPF and DKIM on your domains.
SPF provides host authenticity and DKIM provides a mechanism for checking message integrity.
These protocols do not tell organisations how to handle email, nor do they provide feedback to you, as the sending organisation.
This is the role of DMARC, which builds on top of SPF and DKIM.
Within 24 hours of publishing your DNS records with a DMARC policy of ‘none’, you’ll start receiving email reports from major email recipient domains. These will come to the two addresses you specified in your DMARC record. The first of these should be the anti-spoofing management tool you chose in Step 1, and the second to a back-up email address of your choice, if you included one.
The information in the reports will show:
During this time, you might see a lot a ‘fail’ notices against the SPF and DKIM checks. You should also see a lot of legitimate sources passing checks. For example, you will recognise the IP addresses belonging to your organisation.
The reports will contain information about:
You should use your anti-spoofing management tool to identify legitimate emails which are not passing either SPF or DKIM checks. You should then update your SPF or DKIM configurations so that they do.
To correct SPF failures you should add the sending systems you use to your SPF record, either by IP address, or by reference to another SPF record.
To correct DKIM failures, you should ensure a valid DKIM key is published in the correct place in DNS, and that outbound emails are being signed with it.
You may not recognise all of the sending systems listed in your reports. When this happens you should investigate to determine if a particular sending service is in use by your organisation.
It will likely take a few iterations of investigating, updating records, and waiting to review reports will be needed before you can gain enough confidence that you've got SPF and DKIM working for all of your sending systems.
Once you've reached this stage, you're ready to move to a DMARC policy of 'quarantine' which will provide anti-spoofing protections for your domain.


