Tackling Email Spoofing and Phishing
blog.cloudflare.com
blog.cloudflare.com
Couple of details though:
1. The diagram for DMARC shows that an email is only delivered if it passes both SPF and DKIM. That's not accurate. It only needs to pass one of them.
Emails that you send, but don't control the final delivery such as email user groups and forwarding address like collegiate "alumni" addresses, will fail your domain's SPF but pass DKIM.
Likewise if DKIM is missing a receiving server doesn't have any way to know if it was supposed to be there. DMARC takes out the guess work.
People will reference your documentation as authoritative and it's critically important that you get that right.
2. I LOVE the one click "disable email for this domain" option. That is a fantastic addition and IMO you should make this the default for newly registered domains as a best practice (all registrars should). This is a point that I make during every talk that I give on DMARC.
3. Please, please, please remind people to rotate their DKIM keys if they have been manually entered. Annually would be fine. Many email senders like Sendgrid, Proton and others have started setting up dual CNAME records for DKIM so that they can manage rotation automatically but so many other don't. Tracking and warning people will be a huge benefit.
*Source, spent several years in the DMARC industry.
This is problematic because they are often different in practice, and while SPF acts on the envelope address, DKIM acts on the header address. The recipient typically only sees the header address in their email software. Because of this, SPF on its own is not very useful as a way to avoid spoofing. It does prevent backscatter, however, because bounces are sent to the envelope address.
When a DMARC record is present for the header address domain, the envelope address domain is required to match the header address domain for an SPF check to be considered valid. This makes SPF much more useful when combined with DMARC. Sadly that also makes mail forwarding a harder problem for the same reason - which is interesting given that Cloudflare just started offering an email forwarding service…
While these standards are useful to prevent spoofing, a more practical reason to use them is that end user mail services don't tend to like you very much if you don't. Microsoft (Outlook), for example, is notorious for outright rejecting messages if they don't have valid DMARC.