Sunday, October 4, 2026
GovTech & Cybersecurity Standards Benchmark
Global Digital Verification
✕
Email Security & DNS • 2026 Reference Peer Reviewed

DNSSEC, DMARC, DKIM & SPF: Complete Domain Anti-Spoofing Hardening Guide

The definitive administrator manual for configuring SPF, 2048-bit DKIM selectors, DMARC p=reject enforcement, and DNSSEC cryptographic validation.

WebOTG Standards Directorate
16 mins
Oct 04, 2026
0 views
Advertisement

1. Executive Summary & Email Authentication Architecture

Email is inherently unauthenticated by design. The Simple Mail Transfer Protocol (SMTP) allows any client to specify arbitrary sender addresses in the From: header, making domain spoofing, phishing, and Business Email Compromise (BEC) prevalent attack vectors. To secure domain reputation and protect citizens, international standards (NIST SP 800-177) and CERT-In national directives mandate the implementation of a four-layer authentication architecture: SPF, DKIM, DMARC, and DNSSEC.

Standard Mapping
RFC 7208 (SPF) • RFC 6376 (DKIM) • RFC 7489 (DMARC) • RFC 4033-4035 (DNSSEC) • NIST SP 800-177
Protocol Primary Function Validation Mechanism Failure Outcome
SPF (Sender Policy Framework) Authorizes which IP addresses can send mail for your domain. DNS TXT record query of sender IP against authorized range. SoftFail (~all) or HardFail (-all).
DKIM (DomainKeys Identified Mail) Guarantees email body and headers were not tampered in transit. Cryptographic asymmetric signature verified via public key in DNS. Signature verification failure; message treated as untrusted.
DMARC Coordinates SPF & DKIM alignment; tells receiving servers what to do with failed mail. Domain alignment check between From: header and authenticated domains. None (p=none), Quarantine (p=quarantine), or Reject (p=reject).
DNSSEC Prevents DNS spoofing and cache poisoning of your SPF/DKIM records. Cryptographic chain of trust verified from the root DNS zone down. BOGUS status; receiving resolver drops poisoned DNS answer.

2. Step-by-Step DNS Record Configuration

Step 1: Configure Sender Policy Framework (SPF)

Create a single DNS TXT record for your apex domain. Avoid multiple SPF records, which cause immediate SPF PermError:

# Record Name: @ (or domain.com) # Type: TXT # TTL: 3600 v=spf1 ip4:198.51.100.25 include:_spf.google.com include:mailgun.org -all # Explanation: # - ip4: Authorizes your primary mail server IP. # - include: Delegates authorization to trusted relay services. # - -all: HARD FAIL: Strictly disallows any other unlisted sending servers.

Step 2: Deploy DomainKeys Identified Mail (DKIM)

Generate a 2048-bit RSA keypair (or Ed25519) and publish the public key at selector._domainkey.domain.com:

# Record Name: 202610._domainkey # Type: TXT # TTL: 3600 v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx4QZ7...IDAQAB

Step 3: Enforce DMARC (Domain-based Message Authentication)

Publish your policy at _dmarc.domain.com. Never stay on p=none indefinitely—move to p=reject to eliminate spoofing:

# Record Name: _dmarc # Type: TXT # TTL: 3600 v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; rua=mailto:[email protected]; pct=100 # Key Parameters: # - p=reject: Instructs receiving servers to drop unauthenticated emails outright. # - sp=reject: Enforces the reject policy on all subdomains. # - adkim=s & aspf=s: Enforces STRICT alignment (header domain must match exact signing domain). # - rua: Destination address for daily aggregate XML failure reports.

3. Testing & Verification with dig CLI

Verify your live DNS records using standard terminal commands:

# Verify SPF record dig TXT target-domain.gov +short | grep "v=spf1" # Verify DMARC record dig TXT _dmarc.target-domain.gov +short # Verify DKIM record (replace with your active selector) dig TXT 202610._domainkey.target-domain.gov +short # Test DNSSEC validation dig DNSKEY target-domain.gov +multiline dig A target-domain.gov +dnssec +short

4. Domain Anti-Spoofing Audit Checklist

Checkpoint Compliance Standard Pass Criteria
SPF Hard Fail End policy with -all instead of ~all or ?all. Unauthorized senders rejected at SMTP envelope phase.
SPF Lookup Limit Total DNS lookups (include, a, mx) must not exceed 10. No PermError caused by RFC lookup limit exhaustion.
DMARC Enforcement Policy configured to p=quarantine or p=reject with pct=100. Zero spoofed emails delivered to user inboxes.
DNSSEC Signing Zone signed with valid DS records published at parent registrar. Cryptographic validation passes with no BOGUS flags.
Advertisement
WE
WebOTG Standards Directorate
Principal Systems Auditor

WebOTG provides benchmark reference documentation, automated matrix evaluators, and security test harnesses for government digital platforms, WQMS architectures, and STQC compliance frameworks.