Email Spoofing with DKIM Enabled

Hi all,

My email is being spoofed :pensive_face: It started a week or so before I saw the new DKIM update you can enable in the domains manager (which is now enabled of course). I’m wondering, because this article about the release mentions DMARC, is there anything I can do additionally to prevent the spoofing? I’ve understood that DMARC is the anti-spoof measure, so if it’s already setup I’m not sure what else I can do. Or if I should set it up myself in the DNS?

I’m not too worried about the spoofing for me but if my clients end up getting spoofed, they also already have DKIM enabled so I’d want to have a solution. Any thoughts?

Thanks!

Hi Olivia,

If your domain is managed directly within Sitejet’s Domain Manager, then DKIM, SPF and DMARC are typically configured automatically once DKIM is enabled.

However, if your domain’s DNS is hosted externally (e.g. Cloudflare or another provider), then DMARC would still need to be set up manually in your DNS.

So it really depends on where your domain is managed — if it’s fully inside Sitejet, you likely don’t need to add anything extra :+1:

Gotcha, so my domain is entirely in Sitejet but I am still regularly getting spoofed emails.

Hey Olivia,

Please send us a ticket with a link to this thread, as well as the Website ID, the domain and mail address and some more info. Happy to take a look at this.

Thanks!

After checking the details of this case, we came to the following conclusions:

  • SPF, DKIM, and DMARC are essential authentication protocols to prevent email spoofing and improve sender reputation.

  • The mails in question are spam mails where the recipient is on a mailing list and gets these mails via BCC.

To avoid spam mails, please consider this article as a starting point: https://help.sitejet.io/hc/en-us/articles/24275958598295-How-to-avoid-spam-mails-with-Sitejet

:pray: