How to Stop Email Spoofing of Your Domain
Email spoofing is when someone sends mail that looks like it comes from your domain. It is used for phishing and invoice fraud. Three DNS records, set up together, shut most of it down.
Step 1: List your senders
Write down every service that sends email as your domain: your mailbox provider, newsletter tool, invoicing software, website forms and help desk.
Step 2: Publish SPF and DKIM
Add one SPF record that includes each sender, and turn on DKIM signing in each service that supports it.
Step 3: Add DMARC and tighten it
Publish DMARC with p=none and a report address, review the reports for a few weeks, then move to quarantine and finally reject.
Step 4: Protect domains that never send
Parked or unused domains can be spoofed too. Give them v=spf1 -all, a DMARC record with p=reject, and a null MX record so nobody can use them for mail.
v=spf1 -all
