E-Mail-Authentifizierung & DMARC8 min read2 sections

Introduction to Email Authentication

Why email authentication matters and how SPF, DKIM, and DMARC work together to protect your domain.

01

Why Email Authentication Matters

Every day, billions of emails are sent worldwide — and a significant portion of them are fraudulent. Phishing attacks, CEO fraud, invoice manipulation, and brand impersonation are among the most damaging cyber threats businesses face today. The fundamental problem? Email was never designed with authentication in mind.

The original SMTP protocol (Simple Mail Transfer Protocol), created in 1982, allows anyone to send an email claiming to be from any address. There is no built-in mechanism to verify that the sender is who they claim to be. This is equivalent to a postal system where anyone can write any return address on an envelope.

The Real-World Impact

  • Financial Loss: Business Email Compromise (BEC) caused over $2.7 billion in losses in 2023 alone (FBI IC3 Report).
  • Brand Damage: When attackers send phishing emails using your domain, your customers lose trust — even though you did nothing wrong.
  • Deliverability: Without proper authentication, legitimate emails from your domain are more likely to be flagged as spam or rejected entirely.
  • Legal Liability: In some jurisdictions, organizations can be held liable for not implementing reasonable email security measures.

The Authentication Trinity

Three technologies work together to solve the email authentication problem:

  1. SPF (Sender Policy Framework): Defines which mail servers are authorized to send email on behalf of your domain.
  2. DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to emails, proving they haven't been tampered with in transit.
  3. DMARC (Domain-based Message Authentication, Reporting & Conformance): Ties SPF and DKIM together with a policy that tells receivers what to do with unauthenticated emails, and provides reporting.

Think of it like airport security: SPF is the approved airline list (who is allowed to operate flights), DKIM is the tamper-evident seal on luggage (proving nothing was changed), and DMARC is the security policy that says what to do when something doesn't check out.

02

How SPF, DKIM, and DMARC Work Together

Understanding how these three protocols interact is crucial for proper implementation. Here's the complete flow when an email is received:

Step-by-Step Authentication Flow

  1. Sender sends email: The sending mail server connects to the receiving mail server via SMTP. The email includes envelope information (MAIL FROM) and message headers (From:).
  2. SPF Check: The receiving server looks up the SPF DNS record for the domain in the MAIL FROM (envelope sender). It checks if the sending server's IP address is listed as authorized.
  3. DKIM Check: The receiving server looks for a DKIM-Signature header in the email. If found, it retrieves the public key from the sender's DNS and verifies the cryptographic signature.
  4. DMARC Check: The receiving server looks up the DMARC DNS record for the domain in the From: header (the visible sender). It then checks:
    • Did SPF pass AND is the SPF domain aligned with the From: domain?
    • Did DKIM pass AND is the DKIM domain aligned with the From: domain?
    • If at least one of these passes, DMARC passes.
  5. Policy Enforcement: If DMARC fails, the receiving server follows the DMARC policy: none (monitor only), quarantine (flag as suspicious), or reject (block the email).
  6. Reporting: The receiving server sends Aggregate Reports (XML) back to the domain owner, detailing which emails passed or failed authentication.
Key Insight: DMARC is the only protocol that links the visible sender (From: header) to the authentication results. Without DMARC, an attacker could pass SPF and DKIM checks using their own domain while spoofing your domain in the From: header.