Strategy · Security
DMARC and email deliverability
How Macktez used SPF, DKIM, and DMARC to help a retail client reliably deliver 3-5 million monthly emails while blocking spoofing of its domain.
January 30, 2023
A retail client recently asked us a hard question: can Macktez help them deliver 3-5 million emails a month to verified subscribers, from multiple platforms, without getting tagged as spam?
Why is that so hard? A lot has changed in technology over the past four decades, but the core protocols for sending and receiving email were solidified in the 1980s and have not. That leaves plenty of room for mess, misuse, and misunderstanding, both for people trying to separate signal from noise in their own inboxes and for organizations that rely on large email campaigns to reach their customers and drive business.
The problem
Google and Microsoft in particular have been attacking the spam problem aggressively, flagging email they recognize as spam or phishing and encouraging users to take cybersecurity seriously.
But what about organizations like our retail client that legitimately need to send a high volume of email, want that email delivered, and want to make sure no one is sabotaging their online identity with spoofs and malicious content?
The answer involves a number of acronyms and backend services, plus continued human attention to manage and monitor configuration changes. The tools are useful for any organization concerned with its online reputation, and especially impactful for any with high-volume email requirements.
Tools
First, the acronyms:
- SPF (Sender Policy Framework) is a protocol for letting the world know which outgoing mail servers are allowed to send email from your domain.
- DKIM (Domain Keys Identified Mail) is a protocol that proves an email claiming to come from your outgoing mail server really did.
- DMARC (Domain-based Message Authentication Reporting and Conformance) is a protocol that leverages SPF and DKIM to produce detailed reporting on all email associated with your domain name, and then lets you send specific instructions to recipients' mail servers about what to do with invalid email.
Configured properly, used together, and then monitored and adjusted over time, these tools can greatly reduce cybersecurity risks and increase deliverability for legitimate email. (We include these tools and services in Macktez Domain Management as a monthly subscription.)
When a company receives all its email through Google, for example, but sends email using Mailchimp, SPF, DKIM, and DMARC all need to work together to ensure the Mailchimp email isn't flagged as spam.
Our retail client uses several marketing and retail services to send 3-5 million emails per month on the company's behalf. The sheer volume requires careful policy to make sure the email reaches its intended audience, and each service used to send email needs to be incorporated into the DMARC policy and monitored.
What we did
We spearheaded the Domain Management project with our client. First, we confirmed or established correct SPF and DKIM records for every service the client uses to send email. Then we wrote a DMARC policy that at first only collects information on all email alleging to come from the client's domain.
Once we had enough data, we worked closely with several key members of the client's staff to make adjustments and additions to the policy, slowly raising the percentage of invalid emails that DMARC would instruct recipient mail servers to quarantine or reject outright. This part of the process needs to be done incrementally and with ongoing attention to make sure the policy is applied correctly. It's important not to rush it, or you run the risk of legitimate emails getting blocked.
Results
Within the first two months, DMARC reporting confirmed that the number and percentage of sent emails delivered properly had gone up. Two more months of monitoring and policy adjustments showed that percentage continuing to increase: authentic messages were delivered as intended, while illegitimate messages (spoofing attempts sent from non-authorized servers) were consistently flagged.
This let our client feel confident that its marketing and sales emails were reaching customers, and that any malicious attempts to subvert its domain reputation were being blocked.
The client's marketing, sales, and customer experience teams benefit from knowing their email is sent with proper authentication and received without issue, while their customers get the added security of knowing that spoofing attempts appearing to come from the company won't even make it to their inbox.