Email Authentication Fundamentals
Why spoofing works, what SPF, DKIM and DMARC each assert, and how to reach enforcement without blocking your own mail.
- lessons
- 26
- total
- 4 h
- level
- Beginner
You will be able to
- Read any SPF record and predict its result for a given sending IP
- Find a domain’s DKIM keys and judge whether they are fit for use
- Say exactly what a receiver does with a message that fails DMARC
- Explain why mail passes SPF and DKIM and still fails DMARC
- Tell your own senders from everyone else in an aggregate report
- Build a staged path to p=reject with go/no-go criteria
Syllabus
1. How Email Delivery Works
The path a message takes, the SMTP conversation, and where DNS enters.
2. Why Email Spoofing Works
The two From addresses, why forging either is trivial, and the header receivers stamp.
3. SPF Fundamentals
What SPF asserts, its syntax and evaluation order, and the two limits that break it.
4. DKIM Fundamentals
What a signature proves, how to find the key, and how to judge it.
5. DMARC Fundamentals
The gap SPF and DKIM leave, the policy record tag by tag, and how receivers evaluate it.
6. Alignment
The step between “SPF passed” and “DMARC passed”, and why forwarding changes the answer.
7. Moving Toward Enforcement
Reading aggregate reports, identifying senders, and the staged path to p=reject.
8. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
Email Authentication Fundamentals
- Complete every lesson in Email Authentication Fundamentals
- Pass the final assessment with at least 80%
CertaDNS Engineering · last reviewed