Making Email Security Work for Your Business
Email remains the most common attack vector. How SPF, DKIM, and DMARC protect against spoofing, and which organizational measures complete the picture.

Email remains the most important communication channel for most businesses - and, at the same time, the most common attack vector. Spoofed senders, phishing links, and malware-laden attachments don't just target large enterprises: SMEs are considered particularly attractive targets, since their email infrastructure is less often professionally secured.
Why sender addresses can be forged
The classic email protocol was never designed with security in mind - without additional safeguards, a sender address can be forged relatively easily ("spoofing"). Many attacks rely on exactly this: an email that appears to come from management or a known supplier looks trustworthy, even though it was actually sent by an attacker.
The technical foundation: SPF, DKIM, and DMARC
Three established standards close exactly this gap:
- SPF (Sender Policy Framework) defines which servers are allowed to send email on behalf of a domain.
- DKIM (DomainKeys Identified Mail) cryptographically signs outgoing emails, so tampering in transit becomes detectable.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) defines what should happen to emails that fail SPF or DKIM checks - and provides reports on delivery attempts made in the name of your own domain.
The BSI explicitly recommends that businesses with their own domain configure these three standards correctly; often just a few targeted adjustments to DNS configuration and the groupware in use are enough. DANE and MTA-STS additionally strengthen transport encryption between mail servers.
Phishing remains the most effective attack path
Even correctly configured technical standards don't protect against every attack: a phishing email sent from an actually compromised, legitimate account passes SPF and DKIM checks without issue. That's why raising staff awareness remains essential - for example through regular, realistic phishing simulations that show how well suspicious messages are actually spotted in everyday work.
Encrypting confidential content
For content with special protection needs - contract drafts, HR data, financial information - transport encryption between servers alone is often not enough. End-to-end encryption ensures content stays protected even if a mailbox or a server along the delivery path is compromised.
Organizational measures that belong here
- Clear reporting channels for when employees receive a suspicious email or accidentally click a link.
- Two-factor authentication for email accounts, so a stolen password alone isn't enough for access.
- Regular review of DMARC reports to catch abuse attempts against your own domain early.
- A defined process for payment approvals that doesn't rely solely on an email instruction (protection against "CEO fraud").
Checklist
- Are SPF, DKIM, and DMARC correctly configured for all domains in use?
- Are DMARC reports reviewed regularly?
- Are spam and malware filters active and kept up to date?
- Do employees know the reporting channel for suspicious emails?
- Is two-factor authentication enabled for email accounts?
- Do payment approvals require more than a single email instruction?
Conclusion
Email security isn't a one-time setup, but a combination of correctly configured technical standards, active filtering, and alert employees. With our Anti-Spam and Anti-Virus we reliably filter out threats before they reach the inbox; our Security Awareness & Phishing Simulation sharpens your team's eye for the risks that remain. Get in touch via our contact page if you want to put your email security to the test.


