<< Navigate Whitepages << Baseline

Enterprise Email Infrastructure: Security Baseline and Best Practices - SPF

Sender Policy Framework (SPF)

SPF is an email authentication technique that helps prevent spammers from sending messages on behalf of your domain. It allows the receiving mail server to check that an email claiming to come from a specific domain comes from an IP address authorized by that domain’s administrators.

The above diagram showcases how the receiving server can verify if a domain allows a sender's IP address as an "Authorized" server for the domain Note that SPF is one of the mechanisms to authorize the source of the email. If an SPF validation successfully passes, the receiving server will still proceed with further threat analysis based on the configurations of the email service provider being utilized in the enterprise. If an SPF failure is detected, the course of action for the email is mentioned within the DNS record itself or determined by the policy ('p') tag in the DMARC record of the domain. Additionally, certain Email providers also have various configurations to specially deal with the outcome of DNS failures for the sending server.

We shall discuss more on Security Hardening of the Enterprise Email solutions in the upcoming articles. Now, let's move on to DKIM

DokmainKeys Identified Mail (DKIM) >>