30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification
Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

5.5.3. Email Security and DNS Filtering

💡 First Principle: Email remains the top attack vector, and DNS is the backbone of all internet communication. Securing both dramatically reduces the organization's attack surface because nearly every attack involves one or both — phishing relies on email delivery, and malware relies on DNS for command-and-control communication.

Email security protocols work together as a chain of verification:
  • SPF (Sender Policy Framework) — DNS record listing authorized sending servers for a domain. Receiving servers check if the sender's IP is authorized. Prevents email spoofing from unauthorized servers. Limitation: doesn't validate the "From" header that users see.
  • DKIM (DomainKeys Identified Mail) — adds a digital signature to outgoing email that receiving servers verify against a public key in DNS. Proves the email hasn't been modified in transit. Limitation: doesn't specify what to do when verification fails.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance) — builds on SPF and DKIM to tell receiving servers what to do when authentication fails (none, quarantine, reject) and provides reporting back to the domain owner. DMARC closes the gaps that SPF and DKIM leave individually. The receiving server records each verdict in the Authentication-Results header (spf=, dkim=, dmarc= with pass/fail/none), which is how an analyst reads the outcome from a message's headers. SPF is evaluated against the envelope sender (shown in the Return-Path header), not the From address the user sees; DMARC closes that gap by requiring the domain that passed SPF or DKIM to align with the visible From domain (RFC 7208, RFC 7489, RFC 8601). S/MIME and PGP do a different job: they sign and encrypt the content of individual messages, whereas SPF/DKIM/DMARC authenticate the sending domain and provide no confidentiality.

Email gateway — an appliance or service that inspects all inbound and outbound email for malware, phishing, spam, and data loss. Sits between the internet and the email server. Modern gateways use sandboxing to detonate suspicious attachments, URL rewriting to check links at click time, and machine learning to detect social engineering patterns.

DNS filtering — blocking DNS resolution for known-malicious or policy-violating domains. If the DNS query for a malicious domain never resolves, the connection never happens. Effective because almost all malware and C2 communication relies on DNS. DNS filtering can be applied at the network level (DNS servers or firewalls) or at the endpoint level (DNS agents).

⚠️ Exam Trap: SPF, DKIM, and DMARC work together. SPF validates the sending server. DKIM validates message integrity. DMARC tells receivers what to do when SPF or DKIM fails and provides reporting. All three should be implemented together for effective email authentication.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications