Guidance
Email security and anti-spoofing
A guide for IT managers and systems administrators
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 1 of 14

This guidance is intended to help you secure your organisation's email systems, in two distinct ways:
This will be achieved by configuring effective anti-spoofing controls on your domains. In summary:
• Sender Policy Framework (SPF) allows you to publish IP addresses which should be trusted for your domain.
• Domain Keys Identified Mail (DKIM) allows you to cryptographically sign email you send to show it’s from your domain. Although DKIM is not as widely supported as SPF, it has the advantage of being able to support forwarded email.
• Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.
Your service should be capable of sending and receiving email using Transport Layer Security (TLS).
The NCSC's email security check service can test if an email domain has been correctly configured in line with the standards set out in this guidance.
You should protect all of your organisation's domains, including where your organisation uses common Cloud email providers, such as Google G Suite and Microsoft O365.
This guidance assumes readers have prior knowledge and experience of managing domains and email systems for their organisations.
We have provided links to guidance at the end of this article under Further reading.
When you implement anti-spoofing measures and secure your email while in transit, you:
This list of benefits might be useful additions to any business case arguing for the implementation of these measures - especially when you use external providers.


