While email is in many ways like our digital passport, it was built in 1982 with zero authentication. SPF, DKIM, and DMARC are the patch. Here is how each one works and how they stop phishing TOGETHER
The two-sender explanation is the hinge because DMARC closes an alignment gap, not every impersonation path. When a reject policy is honored, it can stop an unauthorized sender from borrowing the exact visible From domain; it does not make a lookalike domain or a compromised legitimate mailbox honest. That boundary is worth keeping in the user-facing explanation.
Last year, I alerted the IT department of a company I was collaborating with about a serious gap in their email protection. To show them how important it was to fix it, I sent an email impersonating their new CEO, with a note that the CEO would not be happy to see that the email had gone through. The first reaction was “How did you do that?”, as if it weren't something we've been doing since we were kids. Regardless of the reaction and all the explanations, a year later the protection was still not configured...
You and I, as managers, know how demanding our roles are, but faced with a demonstration like that, it's incomprehensible that it wasn't immediately prioritized.
Excellent article! Even though the three are already configured in my environments, I still learned a lot from reading it 👍
The two-sender explanation is the hinge because DMARC closes an alignment gap, not every impersonation path. When a reject policy is honored, it can stop an unauthorized sender from borrowing the exact visible From domain; it does not make a lookalike domain or a compromised legitimate mailbox honest. That boundary is worth keeping in the user-facing explanation.
Exactly! It prevents people from borrowing your domain for malicious purposes. The reputational risk is huge here!
Last year, I alerted the IT department of a company I was collaborating with about a serious gap in their email protection. To show them how important it was to fix it, I sent an email impersonating their new CEO, with a note that the CEO would not be happy to see that the email had gone through. The first reaction was “How did you do that?”, as if it weren't something we've been doing since we were kids. Regardless of the reaction and all the explanations, a year later the protection was still not configured...
You and I, as managers, know how demanding our roles are, but faced with a demonstration like that, it's incomprehensible that it wasn't immediately prioritized.
Excellent article! Even though the three are already configured in my environments, I still learned a lot from reading it 👍
Thank you for sharing this experience!
Sometimes it is very difficult to convince people about the existence of very obvious threats. It’s simply so much easier to ignore it.
Anyone can check the records of well-known businesses, and many of them don’t have it set up properly. I was surprised while writing this article.
Thank you! I really appreciate your comment!