CertaDNS

Email Authentication Fundamentals

Why spoofing works, what SPF, DKIM and DMARC each assert, and how to reach enforcement without blocking your own mail.

lessons
26
total
4 h
level
Beginner

You will be able to

  • Read any SPF record and predict its result for a given sending IP
  • Find a domain’s DKIM keys and judge whether they are fit for use
  • Say exactly what a receiver does with a message that fails DMARC
  • Explain why mail passes SPF and DKIM and still fails DMARC
  • Tell your own senders from everyone else in an aggregate report
  • Build a staged path to p=reject with go/no-go criteria

Syllabus

  1. 1. How Email Delivery Works

    The path a message takes, the SMTP conversation, and where DNS enters.

    1. The path a message takes7 min
    2. Inside an SMTP conversation9 min
    3. How DNS decides where mail goes8 min
  2. 2. Why Email Spoofing Works

    The two From addresses, why forging either is trivial, and the header receivers stamp.

    1. The two From addresses9 min
    2. Why spoofing works at all8 min
    3. Reading the Authentication-Results header8 min
  3. 3. SPF Fundamentals

    What SPF asserts, its syntax and evaluation order, and the two limits that break it.

    1. What SPF asserts — and what it does not8 min
    2. The shape of an SPF record7 min
    3. Mechanisms and evaluation order11 min
    4. Qualifiers, and what -all really promises8 min
    5. include, redirect, and nested records9 min
    6. The limits that break SPF10 min
  4. 4. DKIM Fundamentals

    What a signature proves, how to find the key, and how to judge it.

    1. What a DKIM signature proves9 min
    2. Selectors, and finding the key9 min
    3. Anatomy of a DKIM-Signature header10 min
    4. Judging a key: length, test mode, revocation9 min
  5. 5. DMARC Fundamentals

    The gap SPF and DKIM leave, the policy record tag by tag, and how receivers evaluate it.

    1. The gap SPF and DKIM leave open9 min
    2. The policy record, tag by tag11 min
    3. How a receiver evaluates DMARC9 min
  6. 6. Alignment

    The step between “SPF passed” and “DMARC passed”, and why forwarding changes the answer.

    1. What alignment means10 min
    2. Relaxed and strict9 min
    3. Forwarding, mailing lists, and the limits of each protocol10 min
  7. 7. Moving Toward Enforcement

    Reading aggregate reports, identifying senders, and the staged path to p=reject.

    1. Reading an aggregate report11 min
    2. Telling your senders from everyone else11 min
    3. The staged path to enforcement11 min
    4. What p=reject does not stop9 min
  8. 8. Final assessment

    15 scenario questions · 80% to pass · unlimited retakes

    What the assessment covers

Email Authentication Fundamentals

  • Complete every lesson in Email Authentication Fundamentals
  • Pass the final assessment with at least 80%
About the certificates

CertaDNS Engineering · last reviewed