Skip to main content

One of these is not from you.

Your customer has your brand in the From line, your logo and your order-number format. Nothing in the message tells them which one to trust.

Primary Promotions Social

NORTHFELL Orders <orders@northfell-shipping.com>

Your order #A4821 has shipped — track your parcel

Thanks for shopping with us. Your order is on its way. Confirm your delivery address to avoid…

9:41 AM

NORTHFELL <hello@northfell.com>

Your receipt from NORTHFELL

Yesterday

Shopify <no-reply@shopify.com>

Your shipping label is ready

Mon
Inbox · unauthenticated sender, delivered clean Spoofable

Two order confirmations, two minutes apart

Both landed in the same inbox. The only difference is in headers the customer will never open.

Inbox · 09:14 Authenticated

Your order #1042 is confirmed

Yourbrand <orders@yourbrand.com>

SPF
Pass
DKIM
Pass
DMARC
Aligned
Inbox · 09:16 Spoofed · delivered anyway

Your order #1043 needs payment

Yourbrand <orders@yourbrand.com>

SPF
Fail
DKIM
None
DMARC
No policy to enforce

Both were delivered. The second one only fails checks nobody is enforcing.

Publishing DMARC is what turns those failures into a rejection.

Illustrative example · synthetic data · demonstration domains are fictional

The five records that decide it

SPF
Which services may send as you. Shopify, Klaviyo, support tools and workspace mail all have to be listed, and the record has to stay inside its lookup limit.
Pass
DKIM
A signature on each message proving it was not altered in transit, checked per sending service.
Pass
DMARC
The policy telling a mailbox what to do when the first two fail. Without it both results are advisory, and a spoof is delivered like the real thing.
Not published
MX
Where your mail actually routes, so replies and support requests reach the service you expect.
Pass
MTA-STS
Requires receiving mail servers to use an encrypted connection. Optional, and worth having.
Advisory

Read your five records now.