Posted on September 12, 2020 at 11:46 am

Simple steps to make your domain emails not spoofeable:

1) Add a TXT record (SPF):

v=spf1 a mx ~all

Or use include: to include specific hosts or IPs, example:

v=spf1 include:ip4: ~all

2) Add a TXT record (DMARC):

v=DMARC1; p=quarantine; pct=100;;

Or you can use p=reject to reject emails:

v=DMARC1; p=reject; pct=100;;

3) Check your domain name (e.g with these tools:

Here is an example scan report for domain

Found SPF record:
v=spf1 ~all
SPF record contains an All item: ~all
Found DMARC record:
v=DMARC1; p=quarantine; pct=100;;
DMARC policy set to quarantine
Aggregate reports will be sent:
Forensics reports will be sent:
Spoofing not possible for

4) Check DNS TXT/DMARC records of popular domains:

You can copy SPF and DMARC records or popular domains (e.g

Just make sure to edit them with your domain data.

