A client calls you, upset: they received an email that looks like it came from your company, with your name and address, asking them to pay a fake invoice. You never wrote that email. But as far as the recipient can tell, it came straight from you. This kind of impersonation is easier to pull off than most people think, and it targets Quebec SMEs every day.
The good news is there are three free, standard mechanisms that block this kind of fraud and improve delivery of your legitimate emails: SPF, DKIM, and DMARC. Set up correctly, they prove to Microsoft, Google, and other mail servers that messages carrying your domain name really do come from you. Here’s how they work and how to set them up for your business in Mauricie.
Quick answer: SPF, DKIM, and DMARC are three DNS records that authenticate your emails. SPF specifies which servers are allowed to send on your behalf, DKIM adds a digital signature proving the message wasn’t altered, and DMARC tells recipients what to do if verification fails. Together, they block impersonation of your domain and improve your delivery rate.
1. Why your emails end up in spam (or worse)
Email protocols were designed in the 1980s, back when trust was the default on the network. As a result, by default, anyone can send a message with your address in the sender field. That’s exactly what fraudsters exploit to make their scams look like they’re coming from your SME.
When SPF, DKIM, and DMARC aren’t set up, two problems show up. First, your real emails risk landing in your clients’ spam folder, because receiving servers have no way to confirm your identity. Second, your domain becomes an easy target for phishing: an attacker can send hundreds of fake messages in your name without anyone noticing.
- Your invoices and quotes land in the client’s spam folder.
- Scammers send fake payment requests pretending to be you.
- Your sender reputation degrades with Microsoft 365 and Gmail.
- Your legitimate email campaigns get blocked or flagged as suspicious.
For a Trois-Rivières SME that relies on email for invoicing and communication, that means lost sales and damaged credibility. Working with a managed IT services provider closes this door for good.

2. SPF: who’s allowed to send on your behalf
SPF, short for Sender Policy Framework, is the first line of defense. It’s a list published in your DNS that names every server authorized to send emails using your domain name. When a server receives a message, it checks this list: if the sender isn’t among the approved servers, the email gets flagged as suspicious.
For a Quebec SME on Microsoft 365, the SPF record includes Microsoft’s servers plus any third-party service sending on your behalf: your newsletter tool, your invoicing system, your CRM. This is the step most often forgotten, and the one that causes the most legitimate emails to get blocked.
What SPF doesn’t do
SPF checks the technical envelope of the message, not the visible sender field. So a fraudster can sometimes slip through the cracks if you rely on SPF alone. That’s exactly why it needs to be paired with DKIM and DMARC, and why you should never stop at just one of the three.
3. DKIM: the signature that proves authenticity
DKIM, short for DomainKeys Identified Mail, adds a digital signature to every outgoing email. That signature is generated with a private key only you hold, and the receiving server verifies it using a public key published in your DNS. If the message was altered along the way, the signature no longer matches and the email gets rejected.
In practice, DKIM answers two questions: does this message really come from your domain, and is its content intact? It’s cryptographic proof that’s hard to fake. In Microsoft 365, DKIM is set up in a few clicks in the admin center, then activated by publishing two DNS records.
- The signature travels with the email, invisible to the recipient.
- It confirms the content hasn’t been tampered with.
- It strengthens your reputation with major providers.
- It’s required for DMARC to work properly.

4. DMARC: the policy that brings order
SPF and DKIM verify. DMARC decides. It’s the policy that tells receiving servers what to do when an email fails verification: let it through, quarantine it, or reject it outright. Without DMARC, the first two mechanisms exist, but nobody knows how to respond to a failure.
DMARC also brings a valuable bonus: reports. Every day, you get a summary showing who’s sending emails in your name, how many pass verification, and how many fail. For an SME, that’s a direct window into attempts to impersonate your domain, and a tool for catching a legitimate service that’s misconfigured.
The right progression
You never start with a strict policy. The recommended approach is to begin in monitoring mode, review the reports for a few weeks, then gradually tighten toward quarantine and finally rejection. Moving to rejection too fast risks blocking your own legitimate emails. This fine-tuning is where a bit of experience matters.
5. How to set up SPF, DKIM, and DMARC for your SME
Setup happens entirely in your DNS, where your domain name lives. Here’s the right order to follow for a business on Microsoft 365:
- Publish your SPF record listing Microsoft 365 and any third-party sending services.
- Turn on DKIM in the Microsoft 365 admin center, then publish the two DNS records it asks for.
- Create a DMARC record in monitoring mode, with an address to receive reports.
- Review the reports for two to four weeks to catch any legitimate service that isn’t covered.
- Tighten the policy toward quarantine, then rejection once everything is clean.
Each step sounds simple, but one syntax error in a DNS record can block all your emails overnight. That’s why many Mauricie SMEs prefer to hand this setup to a specialized team. If you’d like a hand, the OKTO team can check everything for you through our contact page.
6. Common mistakes (and how to avoid them)
Across our work with businesses throughout Quebec, certain mistakes come up again and again. Knowing them ahead of time will save you weeks of lost email.
- Two SPF records: you should only ever have one. Two separate SPF records invalidate the check entirely.
- Forgetting a sending service: your newsletter tool or accounting software might be sending in your name without being listed in SPF.
- Moving to rejection too fast: without an observation period, you risk blocking your own communications.
- Ignoring DMARC reports: they contain impersonation signals that need regular monitoring.
- Leaving DKIM inactive: many SMEs publish SPF and DMARC but forget to turn on DKIM in Microsoft 365.
Set up properly, this trio protects your brand, reassures your clients, and keeps your emails out of spam folders. Set up poorly, it becomes a quiet headache.
Frequently asked questions
Are SPF, DKIM, and DMARC free?
Yes, all three are open, free standards. You simply publish records in your domain’s DNS. The only possible cost is technical support if you’d rather delegate the setup than risk a mistake.
How long does setup take?
Technically setting up SPF, DKIM, and DMARC usually takes less than an hour. DNS propagation can take up to 48 hours, and DMARC’s observation phase runs for a few weeks before you can safely tighten the policy.
What happens if I don’t set anything up?
Your legitimate emails are more likely to get flagged as spam, and anyone can send fake communications in your name. For an SME, that’s a real risk of scams targeting your clients and a loss of credibility.
Protect your SME’s email in Trois-Rivières and Mauricie
Email remains your business’s number one channel, and also the top entry point for fraudsters. Setting up SPF, DKIM, and DMARC closes that door while improving delivery of your legitimate messages. Our team supports SMEs across Trois-Rivières and all of Mauricie through this process, from diagnosis to ongoing monitoring. Check out our managed IT services or reach out directly through our contact page for a full review of your domain.