Problem
Many domains send mail through Microsoft 365, website forms, CRMs, marketing platforms, and billing tools, but nobody owns the full sending inventory.
Why it matters in 2026
Mailbox providers and customers increasingly expect authenticated mail. Weak SPF, missing DKIM, or loose DMARC can damage deliverability and make spoofing easier.
Who this affects
- Businesses sending mail from multiple tools.
- Teams preparing vendor security questionnaires.
- Owners seeing spoofed or failed email delivery.
Step-by-step recipe
- List every system that sends as your domain.
- Review SPF for unnecessary includes and DNS lookup limits.
- Enable DKIM for Microsoft 365 and key senders.
- Start DMARC monitoring before enforcing quarantine or reject.
- Review reports and fix unknown senders.
- Document the owner of each sending service.
Common mistakes
- Adding every vendor to SPF without removing old ones.
- Moving DMARC to reject before legitimate senders are aligned.
- Forgetting website forms and ticketing systems.
Downloads and next steps
Printable PDFDownload SPF, DKIM, and DMARC Email Security WorksheetCompanion ProductMicrosoft 365 Email Security ChecklistRelated RecipesContinue learningCyberHouse AssessmentGet implementation help
DIY next step
Create a sender inventory before changing DNS records.
CyberHouse CTA
Want us to handle this for you? CyberHouse can help with Microsoft 365 protection, cyber risk cleanup, ransomware readiness, secure automation, and vendor-ready cyber baseline work.
Visit CyberHouseRelated Recipes
Microsoft 365 Default Settings and QR-PhishingLearn why Microsoft 365 defaults can leave small businesses exposed to QR phishing and what to review first.30-Point Cyber Risk ChecklistA practical cyber risk checklist for small businesses reviewing Microsoft 365, email security, vendors, backups, ransomware readiness, and AI use.Virginia B2B Contractor Vendor Assessment GuideA practical readiness guide for Virginia B2B contractors preparing for customer vendor cyber assessments in 2026.
