1. Executive Summary & Email Authentication Architecture
Email is inherently unauthenticated by design. The Simple Mail Transfer Protocol (SMTP) allows any client to specify arbitrary sender addresses in the From: header, making domain spoofing, phishing, and Business Email Compromise (BEC) prevalent attack vectors. To secure domain reputation and protect citizens, international standards (NIST SP 800-177) and CERT-In national directives mandate the implementation of a four-layer authentication architecture: SPF, DKIM, DMARC, and DNSSEC.
| Protocol | Primary Function | Validation Mechanism | Failure Outcome |
|---|---|---|---|
| SPF (Sender Policy Framework) | Authorizes which IP addresses can send mail for your domain. | DNS TXT record query of sender IP against authorized range. | SoftFail (~all) or HardFail (-all). |
| DKIM (DomainKeys Identified Mail) | Guarantees email body and headers were not tampered in transit. | Cryptographic asymmetric signature verified via public key in DNS. | Signature verification failure; message treated as untrusted. |
| DMARC | Coordinates SPF & DKIM alignment; tells receiving servers what to do with failed mail. | Domain alignment check between From: header and authenticated domains. |
None (p=none), Quarantine (p=quarantine), or Reject (p=reject). |
| DNSSEC | Prevents DNS spoofing and cache poisoning of your SPF/DKIM records. | Cryptographic chain of trust verified from the root DNS zone down. | BOGUS status; receiving resolver drops poisoned DNS answer. |
2. Step-by-Step DNS Record Configuration
Step 1: Configure Sender Policy Framework (SPF)
Create a single DNS TXT record for your apex domain. Avoid multiple SPF records, which cause immediate SPF PermError:
Step 2: Deploy DomainKeys Identified Mail (DKIM)
Generate a 2048-bit RSA keypair (or Ed25519) and publish the public key at selector._domainkey.domain.com:
Step 3: Enforce DMARC (Domain-based Message Authentication)
Publish your policy at _dmarc.domain.com. Never stay on p=none indefinitely—move to p=reject to eliminate spoofing:
3. Testing & Verification with dig CLI
Verify your live DNS records using standard terminal commands:
4. Domain Anti-Spoofing Audit Checklist
| Checkpoint | Compliance Standard | Pass Criteria |
|---|---|---|
| SPF Hard Fail | End policy with -all instead of ~all or ?all. |
Unauthorized senders rejected at SMTP envelope phase. |
| SPF Lookup Limit | Total DNS lookups (include, a, mx) must not exceed 10. |
No PermError caused by RFC lookup limit exhaustion. |
| DMARC Enforcement | Policy configured to p=quarantine or p=reject with pct=100. |
Zero spoofed emails delivered to user inboxes. |
| DNSSEC Signing | Zone signed with valid DS records published at parent registrar. | Cryptographic validation passes with no BOGUS flags. |
WebOTG Standards Directorate
WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.