NHM Ohio blog

SPF, DKIM, and DMARC Basics for Business Email Security

What each control does, how they work together, and the implementation errors that break deliverability.

By Noah Stertzbach, owner of NHM Ohio · Published · Updated

Two coworkers sit at a desk by tall windows, one resting his hands on printed sheets while the other works the laptop trackpad, a printer behind them.
AI-generated illustration

SPF, DKIM, and DMARC are complementary controls. Deploying only one leaves gaps in spoofing protection and mailbox trust.

SPF: who can send mail for your domain

SPF authorizes approved senders in DNS. Keep records concise, remove stale vendors, and avoid multiple SPF records at the same host.

DKIM: cryptographic message signing

DKIM validates that message headers/body were signed by an authorized sender and were not altered in transit.

DMARC: policy and reporting layer

DMARC checks alignment and tells receivers what to do for failures (none, quarantine, reject) and where to send aggregate reports.

Common implementation mistakes

Frequent issues include missing alignment, old third-party senders, and moving to enforcement before all legitimate send paths are validated.

Safe rollout pattern

An IT consultant and an office manager go through notes and a laptop together at a desk by a window.
AI-generated illustration

Start at p=none, review reports, fix alignment gaps, then progressively enforce. Use staged policy increases to avoid legitimate mail loss.

Operational best practices

Track every sending platform, rotate DKIM keys on schedule, and review DMARC reports regularly to catch drift and unauthorized use.

What to do once reports arrive

Receiving reports is the start, not the end. Three things we do for you in DomainGuard so the reports turn into action:

  • We rank the senders in the report by failing-message volume. Unknown IPs with material failure show up first because that is the “we forgot a service” case, which is what breaks enforcement if you do not catch it.
  • We tell you when it is safe to advance from p=none to p=quarantine. The rule is at least two weeks of reports and 95% of mail passing DMARC (aligned SPF or DKIM). We surface that as a banner the day it becomes true, not a chart you have to interpret.
  • When your email starts landing in spam, we tell you which sender is failing and how to fix it. The diagnostic panel runs the per-domain data through a checklist of failure modes — missing DMARC record, broken DMARC record, unrecognised sender, misconfigured ESP — and ranks the most likely cause first.

Need help with IT services or web hosting?

Talk with our team about managed IT support, secure hosting, migration, and day-to-day operations.

About the author

Noah Stertzbach, owner of NHM Ohio

Noah Stertzbach

Owner, NHM Ohio

Noah started NHM Ohio in 2021 and runs it from East Canton, Ohio. Clients work with him directly.

More about Noah and NHM Ohio →

IT Security Tips Newsletter

Weekly insights for Northeast Ohio businesses

Practical security and IT tips for Ohio business owners. No spam, and every email has an unsubscribe link.

DMARC setup guidesPhishing examplesSSL renewal checklistsOhio SMB case studies

Need Help Fixing Email Authentication?

We can review your DNS records, align sending services, and move DMARC policy safely toward enforcement.

Looking for specific offerings? Managed IT services or web hosting services.