Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 1 of 14

A man working at a computer desk with several coloured post-it notes stuck to his monitor.

This guidance is intended to help you secure your organisation's email systems, in two distinct ways:

  • 1

    By making it difficult for fake emails to be sent from your organisation's domains.

    This will be achieved by configuring effective anti-spoofing controls on your domains. In summary:

    • Sender Policy Framework (SPF) allows you to publish IP addresses which should be trusted for your domain.

    • Domain Keys Identified Mail (DKIM) allows you to cryptographically sign email you send to show it’s from your domain. Although DKIM is not as widely supported as SPF, it has the advantage of being able to support forwarded email.

    • Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.

  • 2

    By protecting your email in transit with TLS

    Your service should be capable of sending and receiving email using Transport Layer Security (TLS).

Are you protected? Run a free instant email security check

The NCSC's email security check service can test if an email domain has been correctly configured in line with the standards set out in this guidance.

Learn more and run a check

You should protect all of your organisation's domains, including where your organisation uses common Cloud email providers, such as Google G Suite and Microsoft O365.

This guidance assumes readers have prior knowledge and experience of managing domains and email systems for their organisations.

We have provided links to guidance at the end of this article under Further reading.


Business cases

This list of benefits might be useful additions to any business case arguing for the implementation of these measures - especially when you use external providers.

Published

Reviewed

Version

2.0