GUIDES / TRUST

What email-security checks can and cannot prove.

SPF, DKIM and DMARC decide one narrow, important thing: whether a stranger can send email that claims to be from your domain — and whether the world's mail servers have been told to refuse it. This guide explains what each record does, and is honest about the limits.

Check Your Digital Readiness

01 / THE RECORDS

Four public records, one decision.

SPF

Lists the servers allowed to send mail as your domain. Ending in -all tells receivers to distrust everything else.

DKIM

Signs your outgoing mail so tampering and forgery are detectable by the receiver.

DMARC

Tells receiving servers what to do with mail that fails the checks — and p=reject is the setting that actually refuses forgeries.

MX

Says where your incoming mail is delivered, and reveals which provider runs it.

02 / WHY IT MATTERS HERE

This is a live Kenyan problem, not a theoretical one.

Over one hundred Kenyan parastatal chief executives were put on notice over exactly these records — the full story is in Insights. A domain without them can be impersonated to its own customers, suppliers and bank; most recipients will never spot the difference.

03 / THE HONEST LIMITS

What a clean result does not prove.

  • It does not prove your mailboxes are secure — passwords, sessions and staff phishing are untouched by these records
  • It does not prove mail is delivered, read or answered
  • It does not prove the business is secure or compliant in any general sense
  • It is not a penetration test, an audit or a certificate
Published DNS records are the defence the world can see. The rest — mailbox access, recovery, staff practice — is exactly what the human-reviewed readiness assessment examines.

YOUR NEXT STEP

Start with the problem - not the supplier.

Identify the priorities, understand the responsibility and then continue through the route that fits the work.