Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours

Information Email Security

Email security using the simplest of methods!

Email is the most important means of communication in day-to-day business - and, at the same time, the most popular entry point for cyberattacks. Over 90 per cent of all successful attacks begin with a manipulated email. With the right security technologies, you can effectively protect your business against phishing, spoofing and data loss.

90%+
All successful attacks begin with a manipulated email
3
Pillars: SPF, DKIM and DMARC
2024
Google and Yahoo are calling for standards

01Protective measures

Protective measures: The three pillars of email authentication

Modern email security is based on three complementary methods: SPF, DKIM and DMARC. Only the combined use of all three technologies offers comprehensive protection against forgery and misuse. Since 2024, major providers such as Google and Yahoo have required these standards to be implemented correctly - otherwise, your emails may end up in the spam folder.

  1. SPF checks the sending server
  2. DKIM guarantees the integrity of the message
  3. DMARC provides clear guidelines on how to respond to breaches
SPF

SPF method

SPF (Sender Policy Framework) is the first line of defence against email spoofing. The process specifies which servers are authorised to send emails on your behalf.

You publish a special DNS record (TXT record) that lists all authorised IP addresses and mail servers. For every incoming email, the receiving mail server checks whether the sending IP address is listed in the SPF record. If the IP address does not match, the email is flagged as suspicious or rejected.

Setting up SPF records: a step-by-step guide
DKIM

DKIM method

DKIM (DomainKeys Identified Mail) goes one step further than SPF: it not only ensures that the email originates from an authorised server, but also that the content has not been tampered with in transit.

Every outgoing email is provided with a digital signature generated using a private key. The corresponding public key is published in the DNS. The recipient can verify the signature and thus check the authenticity and integrity of the message.

Understanding and implementing DKIM
DMARC

DMARC procedure

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the overarching framework for SPF and DKIM. It sets out binding rules on how emails that fail authentication checks should be handled.

You publish a DMARC policy in the DNS, which specifies whether unauthenticated emails should be delivered (none), moved to the spam folder (quarantine) or rejected entirely (reject). In addition, you will receive regular reports on delivery attempts and any potential attempts to misuse your domain.

none
delivered
quarantine
Spam folder
reject
rejected
Setting up and optimising a DMARC policy

Conclusion: We are only strong when we work together

SPF, DKIM and DMARC complement one another and should always be used together. SPF verifies the sending server, DKIM ensures the integrity of the message, and DMARC provides clear instructions on how to respond to violations. At SpeedIT Solutions, all three methods are pre-configured as standard in our hosting plans - you benefit from maximum email security from day one.

02Security & Detection

Security & Detection: Understanding and Countering Threats

Despite all the authentication measures in place, emails remain a popular target for attacks. You should be aware of the following threats - and know how to protect yourself and your staff from them.

Email address spoofing

In email spoofing, attackers manipulate the sender’s address so that the message appears to come from a trusted source - such as your bank, a colleague or a business partner.

Typical attack scenarios:

  • CEO fraud: A fake email from the managing director containing an urgent payment instruction
  • Supplier fraud: A falsified invoice with altered bank details
  • Credential harvesting: Fake login prompts designed to steal login details

The consistent implementation of SPF, DKIM and DMARC makes spoofing considerably more difficult. In addition, staff should receive regular training in recognising suspicious emails.

Spotting phishing and spoofing: the key warning signs

DNSBL lists (DNS-based blackhole lists)

DNSBL lists are an important tool in the fight against spam. These lists contain the IP addresses of servers known to be sources of spam. Mail servers around the world use these lists to automatically block suspicious emails.

Why this matters to you: If your mail server ends up on a blacklist - for example, because a user has unwittingly sent spam - your legitimate emails will suddenly no longer reach their recipients. At SpeedIT Solutions, we continuously monitor our IP addresses and respond immediately to any suspicious activity.

Understanding DNSBL lists and checking your own status

Conclusion: Multi-layered protection is crucial

Effective email security requires a holistic approach: the SPF, DKIM and DMARC authentication methods form the technical foundation. These are complemented by premium spam filters, virus protection and staff awareness training. At SpeedIT Solutions, all technical security measures are enabled as standard - you can rely on secure email communication.

  • SPF
  • DKIM
  • DMARC
  • Premium spam filter
  • Antivirus protection
  • Raising staff awareness

Your next step

Communicate securely now

All our hosting plans include professional email security: DKIM, SPF, DMARC, premium spam filters and virus protection - at no extra cost and with no complicated configuration required.

Agency partners

Professional support for agencies.

  1. Initial call

    Personal, about your goals and clients.

  2. Partnership

    Simple contract, dedicated contacts.

  3. Training & support

    Your team knows every detail.