Email & security

Your email has been going out unauthenticated for years

By Leonel Lordeus · Lordeus Pro · 5 min read

I looked at a small practice's domain recently. It had no SPF record and no DMARC record — none, not misconfigured, simply absent. Every message that business had ever sent went out with no way for the receiving server to confirm it was really them. Nobody had ever mentioned it. Why would they? Nothing looked broken.

What these three records actually do

Strip away the acronyms and they answer three plain questions.

Most small businesses have none of the three. Not because anyone decided against them — because the person who set up the email left years ago, and this was never on a list.

Two things it costs you, quietly

More of your mail lands in spam than should. Gmail and Outlook weigh authentication heavily. An unauthenticated domain looks, to a filter, exactly like someone pretending to be you. Your quotes and invoices are competing against that suspicion every time.

Anyone can send email as you. Not as a lookalike domain — as you, from your actual address, to your actual clients. There is nothing in place to stop it and nothing that would tell you it happened.

The mistake that does real damage

Here's where well-meaning fixes go wrong. Someone reads about DMARC, sets it straight to reject, and considers the job done.

Then legitimate mail starts disappearing. Not bouncing — disappearing. And nobody phones to say their invoice never arrived; they just assume you're slow, or they go elsewhere. You find out weeks later, if at all.

The order is the whole job:

  1. Publish SPF and DKIM first. Verify they actually pass.
  2. Set DMARC to none — watch and report, change nothing.
  3. Read the reports for about 30 days. See who is genuinely sending as you.
  4. Only then tighten to quarantine, and later to reject.

The part almost everyone misses

SPF authenticates the envelope sender — the return address the mail servers use — not the "From" address your recipient sees. Those are frequently different.

Which means every service that sends on your behalf has to be accounted for before you enforce: your invoicing tool, your scheduling system, the CRM, the newsletter platform, the contact form on your website. Small businesses routinely have three or four of these and remember none of them until the day they break.

That's why the first thing worth doing isn't touching DNS at all. It's building a list of everything that sends as you.

How to check yours in two minutes

Send an email from your business address to a Gmail account you control. Open it there, click the three dots, and choose Show original. You'll see SPF, DKIM and DMARC each marked PASS, FAIL, or absent entirely.

If they're absent, that's not an emergency — it's been that way for years. But it is worth fixing, and it's worth fixing in the right order.

Not sure what's set up on your domain? The Systems & Operations Audit covers email authentication along with accounts, access, backup and licensing — and tells you in plain English what's exposed. Or just book a free 15 minutes and I'll check the basics with you on the call.

Book a free 15-minute call
← More articles