BUSINESS EMAIL SECURITY

SPF, DKIM and DMARC audit checklist for business email.

Email authentication should show which services may send for a domain, prove that important messages were signed, and tell receiving systems what to do when authentication fails. This checklist helps an owner review that chain before moving to stronger enforcement.

Why all three controls need to be reviewed together

SPF, DKIM, and DMARC solve different parts of the authentication problem. A record can exist and still provide weak protection if legitimate senders are missing, domains do not align, or enforcement is enabled before business systems are ready.

SPF authorizes infrastructure

SPF identifies which servers may use a domain in the technical return path. It should represent current sending services without duplicate records, excessive DNS lookups, obsolete vendors, or an unnecessarily broad authorization.

DKIM signs the message

DKIM lets a receiving system verify that a message carries a valid cryptographic signature for a signing domain. The audit checks selector visibility, alignment, key-management dependencies, and whether important senders actually sign.

DMARC connects identity and policy

DMARC compares the visible From domain with SPF and DKIM results, provides aggregate reporting, and publishes a policy for failed mail. It can pass through aligned SPF, aligned DKIM, or both.

SPF audit checklist

The goal is a controlled list of legitimate senders, not the longest possible record.

CheckEvidence to reviewWhy it matters
One SPF recordConfirm that the domain publishes a single valid SPF policy rather than multiple competing TXT policies.Multiple SPF records can produce a permanent error and make legitimate mail fail authentication.
Sender inventoryMap Google Workspace, Microsoft 365, support platforms, marketing tools, invoicing systems, forms, and transactional services.A forgotten platform may fail after enforcement, while an obsolete include leaves unnecessary authorization.
Lookup pressureReview include, redirect, a, mx, and exists mechanisms that contribute to DNS lookup limits.Nested vendor records can push SPF beyond the permitted lookup budget even when the visible record looks short.
Return-path alignmentCompare the technical envelope domain with the domain shown in the From address.SPF can authenticate a service but still fail DMARC alignment when the two organizational domains differ.
Ending mechanismDocument whether the policy ends in neutral, soft fail, or fail and whether that choice matches the rollout stage.The final mechanism communicates how non-authorized infrastructure should be treated during SPF evaluation.

DKIM audit checklist

A public selector record is only one part of the review. The business also needs evidence that real outbound mail uses the expected signing domain.

Expected selectors resolve

List the selectors assigned by each active sending platform and confirm that their public keys resolve under the correct domain. Missing or mistyped selectors should be traced to the responsible platform.

Signing domain aligns

Compare the DKIM signing domain with the visible From domain. Strict DMARC alignment requires an exact match; relaxed alignment permits the same organizational domain.

Key lifecycle is understood

Record who controls key generation, rotation, selector retirement, and DNS publication. The public audit does not retrieve private keys or access sending accounts.

DMARC audit checklist

DMARC should progress from visibility to enforcement only after legitimate traffic is understood.

CheckWhat to confirmSafe next step
Policy is publishedThe record has valid version, policy, percentage, alignment, and reporting tags with no conflicting DMARC record.Correct syntax before drawing conclusions from report volume or policy behavior.
Aggregate reports arriveThe authorized reporting mailbox receives XML summaries from major providers and the team knows who reviews them.Group records by source, count, SPF result, DKIM result, and alignment before changing policy.
Legitimate sources passBusiness systems are recognized and pass through aligned DKIM, aligned SPF, or both.Fix unexplained failures and remove obsolete sources from the approved inventory.
Subdomains are consideredThe owner understands whether the main policy should also cover active and inactive subdomains.Document every legitimate subdomain sender before applying a stricter subdomain policy.
Enforcement is stagedMonitoring data supports the move from none to quarantine and then reject.Use a controlled percentage and rollback plan instead of making an immediate all-domain change.

How to read a DMARC aggregate report

A DMARC report is telemetry, not automatically an incident alert. It summarizes messages a receiving provider observed for the domain during a reporting period.

Identify the reporter and period

Confirm the reporting organization, report ID, covered timestamps, and published domain policy. A report ID is a unique reference, not an error code.

Review every source

For each source IP, compare message count, visible From domain, DKIM signing domain, SPF return-path domain, authentication results, alignment, and final disposition.

Separate gaps from abuse signals

A known platform with DKIM pass and SPF misalignment may be a configuration gap. An unknown high-volume source that fails both paths deserves a different priority and owner review.

Common business email authentication findings

The report should connect technical evidence to operational impact without claiming that every failure is an attack.

FindingWhat it may causeRecommended response
DKIM passes but SPF is not alignedDMARC can still pass, but delivery depends on one aligned authentication route.Confirm whether the platform can use an aligned custom return path without disrupting delivery.
DMARC remains at p=noneReports arrive, but receiving systems are not instructed to quarantine or reject failed mail.Use collected evidence to prepare a staged enforcement plan after legitimate sources are clean.
Unknown sender fails both checksThe record may represent spoofing, an abandoned service, forwarding behavior, or an unrecorded business tool.Investigate ownership and message volume before authorizing or blocking the source.
Reports are delivered but not reviewedAuthentication changes and new sending sources can remain unnoticed.Assign an owner, review cadence, exception process, and evidence retention period.

Questions business owners ask

These answers keep the audit scope practical and safe.

Can DMARC pass when SPF fails?

Yes. DMARC needs either aligned SPF or aligned DKIM to pass. Recurring SPF failures should still be explained so the business is not unnecessarily dependent on one route.

Should we publish reject immediately?

Usually not. Inventory legitimate senders, validate alignment, review reports, correct gaps, and then move through quarantine and reject in controlled stages.

Do you need mailbox access?

No for the standard public audit. We review DNS, authentication, routing, certificate, alignment, and report posture without reading mail or requesting passwords.

Related domain and security resources

Use these pages to compare the service scope, understand related website controls, and choose the next audit step.

Domain and email audit

Turn authentication records into a controlled fix plan.

The $390 Domain & Email Security Audit reviews public evidence and prepares prioritized recommendations without mailbox access or automatic DNS changes.