Retail & Hospitality

DMARC and email deliverability

How Macktez used SPF, DKIM, and DMARC to deliver 3-5 million emails a month from multiple platforms without getting tagged as spam

Fair Harbor ClothingSecurity

At a Glance

Client
Fair Harbor Clothing — a retail brand sending 3-5 million emails a month to verified subscribers from several marketing and retail platforms.
Problem
High-volume email sent on the company's behalf by multiple third-party services, with no unified authentication policy — leaving legitimate campaigns at risk of being tagged as spam and the domain open to spoofing.
Services
Macktez Domain Management · SPF and DKIM record establishment across every sending service · DMARC policy authoring · deliverability report monitoring · incremental policy tightening in partnership with client staff
Platforms
SPF · DKIM · DMARC · multiple third-party marketing and retail email services
Outcome
Deliverability of authentic messages rose over the first two months and continued climbing through two more months of monitoring and adjustment, while spoofing attempts sent from non-authorized servers were consistently flagged.

The Challenge

Four-decade-old protocols and a very large send volume

Fair Harbor Clothing recently asked us a hard question: can Macktez help them deliver 3-5 million emails a month to verified subscribers, from multiple platforms, without getting tagged as spam?

Why is that so hard? A lot has changed in technology over the past four decades, but the core protocols for sending and receiving email were solidified in the 1980s and have not. That leaves plenty of room for mess, misuse, and misunderstanding, both for people trying to separate signal from noise in their own inboxes and for organizations that rely on large email campaigns to reach their customers and drive business.

Google and Microsoft in particular have been attacking the spam problem aggressively, flagging email they recognize as spam or phishing and encouraging users to take cybersecurity seriously.

But what about organizations like Fair Harbor that legitimately need to send a high volume of email, want that email delivered, and want to make sure no one is sabotaging their online identity with spoofs and malicious content?

The answer involves a number of acronyms and backend services, plus continued human attention to manage and monitor configuration changes. The tools are useful for any organization concerned with its online reputation, and especially impactful for any with high-volume email requirements.

The Tools

SPF, DKIM, and DMARC working together

First, the acronyms:

  • SPF (Sender Policy Framework) is a protocol for letting the world know which outgoing mail servers are allowed to send email from your domain.
  • DKIM (Domain Keys Identified Mail) is a protocol that proves an email claiming to come from your outgoing mail server really did.
  • DMARC (Domain-based Message Authentication Reporting and Conformance) is a protocol that leverages SPF and DKIM to produce detailed reporting on all email associated with your domain name, and then lets you send specific instructions to recipients' mail servers about what to do with invalid email.

Configured properly, used together, and then monitored and adjusted over time, these tools can greatly reduce cybersecurity risks and increase deliverability for legitimate email. (We include these tools and services in Macktez Domain Management as a monthly subscription.)

When a company receives all its email through Google, for example, but sends email using Mailchimp, SPF, DKIM, and DMARC all need to work together to ensure the Mailchimp email isn't flagged as spam.

Fair Harbor uses several marketing and retail services to send 3-5 million emails per month on the company's behalf. The sheer volume requires careful policy to make sure the email reaches its intended audience, and each service used to send email needs to be incorporated into the DMARC policy and monitored.

The Approach

Collect first, then tighten incrementally

We spearheaded the Domain Management project with our client. First, we confirmed or established correct SPF and DKIM records for every service the client uses to send email. Then we wrote a DMARC policy that at first only collects information on all email alleging to come from the client's domain.

Once we had enough data, we worked closely with several key members of the client's staff to make adjustments and additions to the policy, slowly raising the percentage of invalid emails that DMARC would instruct recipient mail servers to quarantine or reject outright. This part of the process needs to be done incrementally and with ongoing attention to make sure the policy is applied correctly. It's important not to rush it, or you run the risk of legitimate emails getting blocked.

The Results

Deliverability up, spoofing flagged

Within the first two months, DMARC reporting confirmed that the number and percentage of sent emails delivered properly had gone up. Two more months of monitoring and policy adjustments showed that percentage continuing to increase: authentic messages were delivered as intended, while illegitimate messages (spoofing attempts sent from non-authorized servers) were consistently flagged.

This let our client feel confident that its marketing and sales emails were reaching customers, and that any malicious attempts to subvert its domain reputation were being blocked.

The client's marketing, sales, and customer experience teams benefit from knowing their email is sent with proper authentication and received without issue, while their customers get the added security of knowing that spoofing attempts appearing to come from the company won't even make it to their inbox.

Outcomes

What we delivered.

  • SPF and DKIM records confirmed or established for every service sending email on the company's behalf
  • DMARC policy authored in collect-only mode first, then tightened incrementally toward quarantine and reject
  • Deliverability of authentic messages up within the first two months, and still climbing after two more months of monitoring
  • Spoofing attempts sent from non-authorized servers consistently flagged
  • Ongoing monitoring and policy adjustment through the Macktez Domain Management subscription