Knowledge Hub · Security

Is an SPF record enough to stop attackers spoofing our email domain?

Email Security & Threat Protection · Answered by FirstNet Technology Services

Short answer

No. SPF only declares which mail servers are allowed to send for your domain, and attackers can still spoof the address your recipients actually see. DMARC is needed to enforce the check: it requires the visible From domain to align with an authenticated SPF or DKIM domain, and tells receiving mail providers to quarantine or reject mail that fails.

In detail

SPF also has practical limits. It is restricted by a DNS lookup count and is easily misaligned when you use several sending platforms, such as Microsoft 365, a marketing tool and an ERP system.

Many organisations have an SPF record but no alignment and no enforced DMARC policy, which leaves their domain open to impersonation. Closing the gap needs three things:

  • SPF and DKIM configured and aligned for every legitimate sending source
  • A DMARC record that moves from p=none to p=quarantine to p=reject
  • Ongoing monitoring, because new platforms start sending as your domain over time

FirstNet's managed SendMarc service does the source discovery and specifies the SPF and DKIM changes, your administrators apply them, and FirstNet validates them before each enforcement step. Cyber insurers and audits increasingly ask whether DMARC is enforced, not just whether SPF exists.

Source: FirstNet Email Security & Threat Protection service page →

Didn’t answer your question?

Call