
A couple of weeks ago we checked the DNS records of every member who has their email address listed on the Business Culture site. We wanted to see how well protected the businesses are locally and the level of security knowledge in the area. Due to DNS being public records we can check legally we decided to see how well protected your email domain really is. The reasoning being, if this isn’t set up correctly, what else isn’t?

We’ll keep this as simple as possible.
What is the threat/danger of not having this implemented – the danger is domain email spoofing. We’ve all heard of spoofing but what actually is it?
In its simplest term, it’s the impersonation of you or your business from a third party bad actor/hacker. Email is a great universal tool but it’s based on very old standards that haven’t changed in decades. Anybody can send an email purporting to be from you. It’s extremely easy to compose that email as if it has come from anyone. There’s nothing that can be done from someone sending that email unfortunately. We do, however, have systems in place to prevent the email being delivered. Unfortunately without those mechanisms in place those emails tend to get through.
We’re going to get a bit acronymy here but don’t worry what they stand for. There are three technologies that are needed to prevent your domain being spoofed.
SPF – A list of locations that are authorised to send emails from you. Usually this is all set up for you when you first create your shiny new email account and if you don’t move from one hosting company to another, it usually is ok. There are 14 businesses on here that don’t have an SPF record. Looking at a trend, they seem to be design and creative businesses. This makes sense as they’ve probably moved hosting platforms at least once as that’s common in that industry.
If you have no SPF record, you often find yourself going straight into other people’s spam/junk folder or just not getting through. That’s because the recipient email server doesn’t like this so marks it as potentially unsafe. Even if you’ve sent emails to that recipient for years, you can find yourself hitting their spam filter if your SPF record is missing or it’s incorrect.
Before we move on to the other two technologies, as mentioned, around 10% of businesses on here have no SPF record at all. We can’t determine without receiving an email from you if the ones that do have a record are even correct so there are at least 10% of businesses on here alone with an issue in this area.
To keep you in further suspense and surprise you even more, out of every business on here, only 3 of you have a fully correct configuration, that’s all three technologies seemingly configured correctly. There are another 13 businesses that have made the effort to implement everything but haven’t done it quite right.
So, the below two technologies are only correctly implemented in around 4% of businesses in this community.
DKIM – This adds crypto security to your email. It authenticates that email is coming from who it says it’s coming from. It also prevents any tampering of your email from a threat actor intercepting it in transit. MS365 and Google Workspace do use this to sign your email against their servers but that isn’t enough to protect your domain yourself.
DMARC – This, in the simplest explanation, is the technology that ties together the previous two. This is the one that one 4% of you have set up correctly. Unfortunately 13 of you have this enabled but have set the parameter to none rather than reject or quarantine which makes it completely ineffective (unless you’re in initial implementation for the first two weeks or so).
When an email server receives an email from anyone, it checks if SPF and DKIM are configured. If neither are, it doesn’t like it but may still send it on as spam. What the server will check for also, is DMARC. This is the mechanism that tells the receiving end what to do with the email if SPF and DKIM fail. If configured correctly it will either drop the email completely or quarantine it. What it also does is report on that for you but that’s a bit beyond what this post is for.
So you’ve got this far and you’re maybe thinking this is so bleak because you’re all smaller businesses and bigger business have this covered as standard. You’d be wrong. We checked some of Hull’s biggest businesses and found a similar trend.
There’s no reason to not have these mechanisms in place. They’re just DNS records and don’t cost any money to implement if you were to do them yourselves or shouldn’t be an expensive proposition to go to your MSP or even come to us.
We will be running through all this in the training we’re offering to members where we can demonstrate this rather than just bombard you with a wall of text.
Please, ask your managed IT service provider to investigate this for you. If you don’t have one, you can email support@heysec.co.uk and we can assist at a special BCH rate.