SPF, DKIM and DMARC: Protecting Your Business Email in Quebec
SPF, DKIM and DMARC are three DNS records that authenticate your email. SPF names the servers allowed to send under your domain, DKIM adds a digital signature proving the message was not altered, and DMARC tells receiving servers what to do when a check fails. Together they block domain spoofing and improve your delivery rate.
A client calls you, angry: they received an email that appears to come from your company, with your name and your address, asking them to pay a fake invoice. You never wrote that message. To the recipient, though, it clearly came from you. That kind of spoofing is easier to pull off than most people think, and it targets Quebec small businesses every day.
The good news is that three free, standard mechanisms block this fraud and improve the delivery of your legitimate email: SPF, DKIM and DMARC. Configured properly, they prove to Microsoft, Google and every other mail server that messages carrying your domain name really come from you. Here is how they work and how to set them up for your Mauricie business.
Quick answer: SPF, DKIM and DMARC are three DNS records that authenticate your email. SPF says which servers may send on your behalf, DKIM adds a digital signature proving the message was not modified, and DMARC tells recipients what to do if a check fails. Together, they block spoofing of your domain and improve your delivery rate.
1. Why do your emails land in junk (or worse)?
The email protocol was designed in the 1980s, back when trust ruled the network. As a result, by default anyone can send a message with your address in the sender field. That is exactly what fraudsters exploit to pass their scams off as communications from your business.
When SPF, DKIM and DMARC are not configured, two problems follow. First, your real email risks landing in your clients’ junk folder, because receiving servers have no way to confirm your identity. Second, your domain becomes an easy target for phishing: an attacker can send hundreds of fake messages in your name and nobody notices.
- Your invoices and quotes land in the client’s spam folder.
- Scammers send fake payment requests while pretending to be you.
- Your sender reputation degrades with Microsoft 365 and Gmail.
- Your legitimate email campaigns get blocked or flagged as suspicious.
For a Trois-Rivières business that depends on email to invoice and communicate, that means lost sales and damaged credibility. Support from managed IT services closes that door once and for all.

2. SPF: who is allowed to send in your name
SPF, short for Sender Policy Framework, is the first line. It is a list published in your DNS naming every server authorized to send email using your domain. When a server receives a message, it consults that list: if the sender is not among the approved servers, the email is treated as suspicious.
For a Quebec business on Microsoft 365, the SPF record includes Microsoft’s servers plus every third-party service that sends on your behalf: your newsletter, your invoicing system, your CRM. That is the step most often forgotten, and the one that causes the most legitimate email to be blocked.
What SPF does not do
SPF checks the technical envelope of the message, not the visible sender field. A fraudster can sometimes slip through if you rely on SPF alone. That is precisely why you combine it with DKIM and DMARC, and never stop at the first of the three.
3. DKIM: the signature that proves authenticity
DKIM, short for DomainKeys Identified Mail, adds a digital signature to every outgoing message. The signature is generated with a private key only you hold, and the receiving server verifies it using a public key published in your DNS. If the message was altered along the way, the signature no longer matches and the email is rejected.
DKIM answers two questions: does the message really come from your domain, and is its content intact? It is cryptographic proof that is hard to forge. In Microsoft 365, DKIM is set up in a few clicks in the admin centre, then activated by publishing two DNS records.
- The signature travels with the email, invisible to the recipient.
- It confirms the content was not altered.
- It strengthens your reputation with the major providers.
- It is required for DMARC to work properly.

4. DMARC: the policy that sets the rules
SPF and DKIM verify. DMARC decides. It is the policy that tells receiving servers what to do when an email fails the checks: let it through, quarantine it or reject it outright. Without DMARC, the first two mechanisms exist but nobody knows how to react to a failure.
DMARC also brings a valuable benefit: reports. Every day you receive a summary showing who is sending email in your name, how many pass the checks and how many fail. For a small business, that is a direct window onto attempts to spoof your domain, and a tool for spotting a legitimate service that was misconfigured.
The right progression
You never start with a strict policy. The recommended method is to begin in monitoring mode, review the reports for a few weeks, then tighten gradually toward quarantine and finally rejection. Jumping to rejection too quickly risks blocking your own legitimate email. That tuning work is what takes a bit of experience.
5. How do you configure SPF, DKIM and DMARC?
The configuration lives entirely in your DNS, where your domain name is managed. Here are the steps in the right order, for a business on Microsoft 365:
- Publish your SPF record listing Microsoft 365 and every third-party sending service.
- Turn on DKIM in the Microsoft 365 admin centre, then publish the two DNS records it asks for.
- Create a DMARC record in monitoring mode, with an address for receiving reports.
- Review the reports for two to four weeks to spot any legitimate service that is not covered.
- Tighten the policy to quarantine, then to reject once everything is clean.
Each step looks simple, but a syntax error in a DNS record can block all your email overnight. That is why many Mauricie businesses prefer to hand this work to a specialized team. If you want a hand, the OKTO team can check everything for you from our contact page.
6. Which mistakes come up most often?
Across our work with Quebec businesses, certain mistakes come back constantly. Knowing them saves you weeks of lost email.
- Two SPF records: you must have only one. Two separate SPF records invalidate the check entirely.
- Forgetting a sending service: your newsletter tool or your accounting software may send in your name without appearing in SPF.
- Jumping to reject too fast: with no monitoring period, you risk blocking your own communications.
- Ignoring DMARC reports: they carry spoofing signals that need regular attention.
- Leaving DKIM off: many small businesses publish SPF and DMARC but forget to enable DKIM in Microsoft 365.
Tuned well, this trio protects your brand, reassures your clients and keeps your email out of the junk folder. Tuned badly, it becomes a silent headache.
Frequently asked questions
Are SPF, DKIM and DMARC free?
Yes, all three are open, free standards. You simply publish records in the DNS of your domain name. The only possible cost is technical help, if you would rather delegate the configuration than risk a mistake.
How long does the setup take?
The technical configuration of SPF, DKIM and DMARC generally takes under an hour. DNS propagation can take up to 48 hours, and the DMARC monitoring phase runs over a few weeks before you tighten the policy safely.
What happens if I set none of it up?
Your legitimate email is more likely to be marked as junk, and anyone can send fake communications in your name. For a small business, that is a real risk of scams aimed at your clients and a loss of credibility.
Protect your email in Trois-Rivières and the Mauricie
Email is still your company’s number one channel, and the first door fraudsters try. Setting up SPF, DKIM and DMARC closes that door while improving the delivery of your legitimate messages. Our team supports businesses in Trois-Rivières and across the Mauricie through the whole process, from diagnosis to ongoing monitoring. Take a look at our managed IT services or write to us through our contact page for a full review of your domain.
An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.