Email security

How to Audit Your Outbound Mail: Fixing SPF, DKIM, and DMARC Settings

A practical recipe for auditing outbound email authentication across SPF, DKIM, and DMARC.

Last Reviewed: July 2026 | Author: Aaron House

Problem

Many domains send mail through Microsoft 365, website forms, CRMs, marketing platforms, and billing tools, but nobody owns the full sending inventory.

Why it matters in 2026

Mailbox providers and customers increasingly expect authenticated mail. Weak SPF, missing DKIM, or loose DMARC can damage deliverability and make spoofing easier.

Who this affects

Step-by-step recipe

  1. List every system that sends as your domain.
  2. Review SPF for unnecessary includes and DNS lookup limits.
  3. Enable DKIM for Microsoft 365 and key senders.
  4. Start DMARC monitoring before enforcing quarantine or reject.
  5. Review reports and fix unknown senders.
  6. Document the owner of each sending service.

Common mistakes

Downloads and next steps

DIY next step

Create a sender inventory before changing DNS records.

CyberHouse CTA

Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.

Visit CyberHouse

Related Recipes