自社を装った詐欺メールを防ぐ「DMARC」を、SPF・DKIMとの関係から、はじめての方向けに整理します。
最終更新: 2026年6月
メールの送信者欄(差出人アドレス)は、技術的には簡単に偽装できます。つまり攻撃者は、あなたの会社のドメインを名乗って取引先や顧客に詐欺メールを送ることができてしまいます。受け取った相手は「正規のドメインから来た」と信じてしまうため、被害はあなたの会社の信頼に直接はね返ります。これを防ぐ仕組みが、SPF・DKIM・DMARC の3点セットです。
DMARC は、ひとことで言えば「自分のドメインを名乗るメールが認証に失敗したとき、受信側にどう扱ってほしいか」を宣言する仕組みです。受信側のメールサーバーは、届いたメールが本当にそのドメインから送られたものかを SPF と DKIM で検証し、その結果と DMARC の指示を突き合わせて、配信するか・迷惑メールに入れるか・拒否するかを決めます。
重要なのは、DMARC は単独では働かないという点です。SPF と DKIM という土台があって初めて意味を持ちます。
3つは、それぞれ別の角度から「このメールは本物か」を確かめます。
「このドメインのメールは、これらのサーバーから送られるはずだ」という許可リストを、あらかじめ DNS に公開しておく仕組みです。受信側は、実際の送信元がそのリストに含まれるかを照合します。
送信時にメールへデジタル署名を付け、受信側が「途中で改ざんされておらず、確かにそのドメインが署名した」ことを検証できる仕組みです。署名の鍵は DNS に公開されます。
SPF と DKIM の結果を受けて、不合格だったメールをどう扱うかを指示します。あわせて、差出人欄のドメインと SPF/DKIM が検証したドメインが一致しているか(整合性、アライメント)も確認するため、より厳密ななりすまし判定ができます。
DMARC の効き目は、ポリシー(p=)の設定で決まります。
p=none のままでは記録を取っているだけで、詐欺メールは止まりません。守るには quarantine または reject まで上げる必要があります。近年、Gmail・Yahoo・Microsoft などの大手メールプロバイダが、一定量以上を送る送信者に SPF・DKIM・DMARC の設定を求めるようになりました。これを満たさないと、正規のメールまで届かなくなる(拒否・迷惑メール送り)ケースが増えています。詳しくは「Gmail・Yahoo・Microsoftのメール送信者要件まとめ」をご覧ください。
最初の一歩は、自社ドメインの現状を知ることです。SPF・DKIM・DMARC がそもそも設定されているか、ポリシーが p=none で止まっていないか、SPF が壊れていないかを把握すれば、次にやるべきことが見えてきます。
Spoofed emails impersonating your company are a real threat. Here's how DMARC — alongside SPF and DKIM — stops them, explained from scratch.
Last updated: June 2026
The From address in an email can be trivially forged. An attacker can send a scam email to your customers or partners, making it appear to come from your company's domain. Recipients trust it because the domain looks legitimate — and when the scam succeeds, your company's reputation takes the hit. SPF, DKIM, and DMARC together are the solution.
In one sentence: DMARC lets you tell receiving mail servers what to do with email that claims to come from your domain but fails authentication. The receiving server verifies the message using SPF and DKIM, then consults your DMARC record to decide whether to deliver it, send it to spam, or reject it outright.
Critically, DMARC does not work alone. It depends on SPF and DKIM as its foundation.
Each of the three checks authenticity from a different angle.
You publish a list of mail servers authorized to send on behalf of your domain in DNS. Receiving servers check whether the actual sending server appears on that list.
Your mail server signs outgoing messages with a private key. The receiver verifies the signature against a public key published in your DNS, confirming the message wasn't tampered with in transit and genuinely originated from your domain.
DMARC instructs receivers what to do when SPF or DKIM fails. It also checks that the From header domain aligns with the domain authenticated by SPF or DKIM — closing a loophole that SPF and DKIM alone leave open.
How strongly DMARC protects you depends on the policy (p=) you set.
p=none, you're only watching — spoofed mail still gets through. You need quarantine or reject to actually block it.Gmail, Yahoo, and Microsoft now require SPF, DKIM, and DMARC from senders who send at volume. Failure to comply means legitimate mail gets rejected or sent to spam. See Gmail, Yahoo & Microsoft Email Sender Requirements for details.
The first step is understanding your current state. Are SPF, DKIM, and DMARC even configured? Is your policy stuck at p=none? Is your SPF record broken? Once you know, the next steps become clear.
Enter your domain to get a free instant report on your SPF, DMARC, DKIM, and MX setup. No sign-up required.
Check for free