Blog
Can your email domain be spoofed?
Without DMARC set to reject, someone can send an email showing your exact address. Here is how to check it for free, and what to fix, in order.
Philippe Daoust, founder
The short answer
Yes, if three DNS records are missing or misconfigured: SPF, DKIM and DMARC. Without DMARC in reject mode, a fraudster can send an email that shows your exact address, and the recipient's mailbox has no instruction to refuse it. You can check this for free, with nothing to install, using our domain checker.
Why this concerns you, even if you never send a newsletter
The fraud that costs a small business the most is rarely a virus. It is an email that appears to come from an executive or a supplier, asking to pay an invoice or to change banking details.
If your domain is unprotected, that email can carry your exact address. Neither your client nor your accountant has any reason to doubt it.
The Canadian Centre for Cyber Security recommends that organizations put SPF, DKIM and DMARC in place precisely to reduce this risk.
The three records, in plain language
- SPF: the list of servers allowed to send on behalf of your domain. Ending in
-all, it says "everyone else is refused". - DKIM: a signature added to every outgoing email, which the recipient can verify.
- DMARC: the instruction given to recipients when an email fails the first two checks. At
p=none, you observe without blocking anything. Atp=quarantine, the fake email goes to junk. Atp=reject, it is refused outright.
A domain is genuinely protected when DMARC is set to p=reject. That is the only step that stops the fake email from arriving.
How to check your domain
- Go to prosperit.tech/en/verify.
- Enter your domain, meaning the part after the @ in your address.
- Read the score and the checks: each one shows its state and its impact.
You see the result without leaving your email address. If you want the detail of what to fix and in which order, you can request the report.
A real example: our own domain
We do not publish our clients' results. We can, however, show you ours. Checked on 26 September 2026 with the same tool, prosperit.tech scores A (96 out of 100):
| Check | State | What it reads |
|---|---|---|
| SPF | Strict | v=spf1 include:spf.protection.outlook.com -all |
| DMARC | Reject | v=DMARC1; p=reject with a reporting address |
| DKIM | Published | selectors selector1 and selector2 (Microsoft 365) |
| MTA-STS | Enforced | encryption is required between servers |
| DNSSEC | Signed | DNS answers cannot be forged |
| BIMI | Partial | logo published, without a brand certificate |
The only incomplete item, BIMI, is optional: it displays a logo in certain inboxes, it does not block fraud.
What to fix, in which order
- Publish one single SPF record listing all your sending services: Microsoft 365, newsletter tool, invoicing software.
- Enable DKIM in every service that sends on your behalf.
- Publish DMARC at
p=nonewith a reporting address, then read those reports. - Move to
p=quarantine, then top=reject, once the reports no longer show legitimate mail failing.
Going straight to reject without reading the reports means risking blocking your own invoicing or your own newsletter.
What this does not solve
DMARC protects your exact domain. It does not stop a fraudster from registering a domain that looks like yours, with one letter changed, nor from breaking into a real mailbox. For that you need multi-factor authentication on accounts, and vigilance on the receiving end.
The big providers already require it
Since 1 February 2024, Gmail requires SPF or DKIM from every sender, and DMARC from those sending more than 5,000 messages a day. Microsoft applies similar requirements to high-volume senders to Outlook.com since 5 May 2025. A misconfigured domain can therefore see its email refused, even with no fraud involved at all.
Frequently asked questions
Can DMARC block my own email?
Yes, if it moves to reject before all your sending services are listed in SPF and signing with DKIM. That is exactly why we start at p=none.
I have Microsoft 365. Is it handled out of the box? No. Microsoft 365 provides DKIM, but you have to enable it for your domain, and DMARC is never published automatically.
Who can make the change? The person or company managing your domain's DNS: your registrar, Cloudflare, or your IT provider.
Next step
Check your domain at prosperit.tech/en/verify. If the score is below A, request the report: we tell you what to fix, in which order, and we can do it with you.
Sources
- Canadian Centre for Cyber Security, Implementation guidance: email domain protection (ITSP.40.065 v1.1): cyber.gc.ca
- Google, Email sender guidelines (in force 1 February 2024): support.google.com/a/answer/81126
- Microsoft, Outlook's New Requirements for High-Volume Senders (30 April 2025, in force 5 May 2025): techcommunity.microsoft.com
A question about your IT?
We answer fast, without jargon, in English or French, and the first conversation costs nothing.