MSG / MSG-02
SPF, DKIM and DMARC domain authentication
Configuring mechanisms that help recipients verify email origin and handle unauthorised use of a domain.

WHEN IT HELPS
A focused response
to a defined need.
CIO, marketing or CISO; domain spoofing, delivery problems or many sending platforms.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Inventory senders
- align SPF/DKIM
- observe DMARC results and progressively move to the approved policy
Deliverables
- Sending-flow inventory
- DNS records
- sender-onboarding procedure and report monitoring
Acceptance evidence
In-scope legitimate senders are validated before stronger enforcement; exceptions and unmanaged flows are documented.
DELIVERY
How the work is structured.
Approach
Map domains and senders; select controls; test in pilot/observation mode; enable gradually; organise exceptions, alerts and support.
Prerequisites & responsibilities
Customer: email/DNS administrators, sending teams and sender approval. Provider: configuration and tests. For financial fraud, involve payment owners.
Scope factors
Mailboxes, domains, volume, connectors, third-party senders and operating scope. Proofpoint or other licenses, storage and recurring service are separate from the project.
Questions to clarify
Who sends on behalf of the domain? Which CRM, billing and marketing systems? Who controls DNS?
IMPORTANT BOUNDARIES
DMARC does not block every fraudulent message or lookalike domain; allow for monitoring and overlooked senders.
No solution blocks every fraud attempt. Overly strict policies can block legitimate messages; pilots, exceptions and business procedures remain essential.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An SME’s email, marketing and payroll systems use one domain. Project: inventory and align sources. Target outcome: strengthen DMARC without disrupting payslips or invoices.
Scenario 02
A brand faces spoofing of its exact domain. Project: deploy monitoring and suitable policy. Target outcome: better control of direct-domain spoofing; lookalike domains remain a separate risk.
Technology and reference context
DNS, SPF, DKIM, DMARC and report-analysis tools; select by volume and requirements.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
