Email authentication, in plain post

How does impersonation work?

Email works like post. The sender's name is simply written on the front. Every one can do that. Let's play it out below, your settings are what makes the difference.

Scroll to post them

Spot the difference
Stop 01 · The sender

Every letter is posted from a real location.

Yours gets picked up from your office. Which building it came from can be checked. The name on the envelope cannot.

Your office
Unknown location
The fake · posted too

The scammer cannot send it from your office.

They write your name on it, but send it from a different location. That happens all the time when you send posts from other locations too.

The fake
travels with you
Stop 02 · Security level 1

SPF is your list of approved posting locations.

You write down every place allowed to post letters as you. Normally these include your normal E-Mail Systems such as your Google or Microsoft Accounts, Marketing & Accounting Tools or specific Servers of your own Infrastructure.

Your list
  • ✓Your Office
  • ✓Google
  • ✓CRM
  • ✓Invoicing
  • ✓Marketing Tool
✓Your Office
Found
SPF passes
Your list
  • ✓Your Office
  • ✓Google
  • ✓CRM
  • ✓Invoicing
  • ✓Marketing Tool
✕Unknown Location
Not found
SPF fails

All letters get a mark.

SPF checks where a letter was posted from. It compares it to your list of approved locations. It marks the letter as passed if it's on the list and as failed if it's not.

Stop 03 · Security level 2

DKIM is a seal nobody else can copy.

Letters get handled on the way. Someone could open yours and change the bank details.

Is this still what the sender sealed?

Change one word and the seal breaks. This one is intact.

DKIM passed
DKIM failed
The fake · unsealed

No seal, so it cannot be verified.

They can't copy your seal, two checks failed and it is still on its way to your customer.

Stop 04 · The distribution center

The marks don't stop arrival. DMARC decides.

SPF and DKIM only mark a letter. You need to say what should happen when a letter fails.

That instruction is DMARC. Over 70% of domains never set it up.

Letter A · from your office
SPFPass
DKIMPass
Letter B · from an unknown location
SPFFail
DKIMFail

What should happen to Letter B?

Your standing order

Pick one
v=DMARC1; p=none

You told the post office to do nothing. Both checks failed, and the letter is handed over anyway. This is the default state of almost every domain.

Customer inbox
Spam folder
Blocked from delivery

Letter B lands in your customer's inbox, past two failed checks, because nobody said not to.

Stop 05 · The other half of DMARC

The post office writes back.

That's where DMARC Reports come into place. Every time you send an email to someone, their provider sends you a report back. Stating exactly how the checks went and what the verdict was.

That's how you spot issues on one of your own tools before it gets blocked, and why you start with monitoring and tighten later.

Who posted letters as youlast 7 days
your office 8,412 Pass
newsletter tool 2,190 Pass
invoicing tool 318 Not set up
unknown sender 1,046 Fail

The short version

Six facts that cover most of what the walkthrough shows.

The sender's name is free text

Any mail server can write any address in the From field. Nothing in email itself compares it with the account that sent the message.

SPF checks the building

Your domain publishes a list of servers allowed to send for it. The receiver looks up the server the message came from. Anywhere else fails.

DKIM checks the seal

Your mail carries a signature that receivers verify against a key on your domain. A forged message has no valid seal.

Failing both does not stop delivery

SPF and DKIM only mark a message as passed or failed. Without a DMARC policy, Gmail and Outlook deliver the fake anyway.

DMARC is the instruction

p=none delivers and reports. p=quarantine sends the fake to spam. p=reject refuses it at the door. Only reject keeps it out of the inbox.

Reports show who sends as you

Receivers send delivery feedback to the address in your DMARC record. That is how you find your own tools before you switch to reject.

Three kinds

Three ways someone can pose as you

A DMARC policy on your domain stops one of them completely. The other two need a different answer.

Exact-domain spoofing

The attacker writes your real domain in the From field, for example invoices@your-company.com. This is what the walkthrough shows. It is the most convincing kind because the address really is yours.

Stopped by DMARC

Lookalike domain

A separately registered domain that resembles yours: a swapped letter, an extra hyphen, a different ending. The attacker owns it and can set up SPF, DKIM and DMARC for it correctly.

Employee training protects

Display-name spoofing

The address is unrelated, but the visible name reads like your CEO or your bank. On a phone, most mail apps show only the name.

Employee training protects

One answer for each

Domain Protection closes the first way. Employee Training covers the other two. Both start with a call.

  • Part 1: your domain

    Domain Protection

    We connect your domain, fix your own senders and switch it to refusing fakes. Guided on calls, every step explained.

    • The ABOK dashboard for your domain
    • Delivery feedback read weekly, in plain words
    • Every sender using your name, listed
    • Your own senders set right, tool by tool
    • The rule moved to refusing fakes, once feedback is clean
    • A written record of what changed and why

    Where it ends

    Your domain refuses fakes. Your real mail arrives as before.

    Book a demo
  • Free in beta

    Part 2: your people

    Employee Training

    Short, hands-on practice in spotting a fake and reporting it, on the tricks your industry actually sees.

    On top of Domain Protection:

    • Phishing training for everyone on your team
    • Scenarios built on the fakes your industry sees
    • The call or message that follows the email
    • A dashboard of who trained and what they caught
    • A monthly note on where your team is exposed

    Where it ends

    Your people catch the fakes your domain can't refuse, and know what to do next.

    Book a demo

Questions about how impersonation works

Short answers to the questions the walkthrough raises.

Why can anyone write my domain in the From field?

Email runs on SMTP, a protocol written in 1982 for a network where every operator was known. The From header is a text field the sending program fills in, and nothing in the protocol compares it with the account that sent the message. Authentication was added later, on top, through DNS records the domain owner publishes: SPF in 2006, DKIM in 2007 and DMARC in 2012. A domain that publishes none of them is as open as email was in 1982.

What do SPF, DKIM and DMARC each check?

SPF checks the server: your domain publishes the list of servers allowed to send for it, and the receiver looks up the server the message came from. DKIM checks the message: your server signs each email, and the receiver verifies the signature against a public key on your domain. DMARC checks that at least one of the two passed for the domain in the From field, and tells the receiver what to do when neither did.

If a forged email fails SPF and DKIM, why is it still delivered?

Because a fail is a mark, not an instruction. The receiver cannot tell whether the failure is a forgery or your own invoicing tool that nobody added to SPF. DMARC is where you give the instruction. With no DMARC record, or with p=none, the receiver is told to deliver. With p=quarantine the message goes to spam. With p=reject it is refused.

What is the difference between p=none, p=quarantine and p=reject?

They are the three DMARC policies. p=none: deliver everything as before and send me reports. It changes nothing for an attacker. p=quarantine: treat mail that fails as suspicious, which in practice means the spam folder. p=reject: do not deliver it at all. Reject is the only policy under which a forged email in your exact domain never reaches the inbox. Most domains that have a DMARC record at all sit at p=none.

Does DMARC stop lookalike domains and fake display names?

No. DMARC protects the exact domain in the From address. A lookalike domain is a different domain that the attacker owns, and a display name is not checked by anyone. Those two need alert people and, for lookalikes, monitoring and takedowns. What DMARC removes is the most convincing kind of impersonation, the one where the address really is yours.

How do I find out who is sending email in my name?

Publish a DMARC record with a reporting address, the rua tag. Gmail, Microsoft, Yahoo and most other receivers then send a daily summary of every server that used your domain, how much it sent and whether it passed. Your own tools show up next to the forgers. That is the list you work through before moving from none to reject, so that nothing of yours gets blocked.

Can I see whether my own domain can be impersonated?

Yes, from outside and in seconds. The free check on this site reads the same three records every receiving server reads and tells you which DMARC policy applies to your domain today. Nothing on your domain is changed and nothing is installed.

Is your name protected, or just written on the front?

Enter your domain. The check reads the same three records Gmail and Outlook read and tells you which policy applies today.

Check your domain

Annika Grunewaldt CEO & Co-Founder
ABOK Security

30 minutes, and you know your next step.

Rather talk it through? Annika looks at what your domain publishes today and what it takes to reach reject without blocking your own mail.

  • 30 minutes, directly with a founder
  • Your domain's records on screen
  • You leave with a clear next step
Book a time