4.5d email security spf dkim dmarc

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/10

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:19 PM on 8/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

11 Terms

1
New cards

Email spoofing

Forging the "from" address on an email so it appears to originate from someone other than the actual sender.

2
New cards

Mail gateway

The device or service that receives inbound email, checks its legitimacy, and decides whether to deliver, discard, or route it to spam.

3
New cards

Mail gateway placement

On-premises mail gateways sit in a screened subnet, since they must communicate with external mail servers on the internet.

4
New cards

Cloud-based mail gateway

Third-party services can provide mail gateway functionality instead of hosting it on-premises.

5
New cards

SPF (Sender Policy Framework)

DNS TXT record listing which mail servers are authorized to send email on behalf of a domain. Checks the sending server's identity.

6
New cards

DKIM (DomainKeys Identified Mail)

DNS TXT record holding a public key used to validate a digital signature applied to outgoing mail during transport between mail servers. Checks message integrity.

7
New cards

DKIM signature scope

The digital signature is added between mail servers during transport, not visible in the message body; found in the email headers.

8
New cards

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

DNS TXT record extending SPF and DKIM, specifying what a receiving server should do when a message fails validation: accept, quarantine, or reject.

9
New cards

DMARC does not check anything itself

DMARC relies purely on SPF and DKIM results; it only defines the policy action to take and provides reporting, it performs no independent validation.

10
New cards

DMARC reporting

Domain owners receive compliance reports showing how many messages validated successfully vs failed, helping detect spoofing of their domain.

11
New cards

SPF vs DKIM

SPF checks whether the sending server is authorized. DKIM checks whether the message was tampered with, via cryptographic signature. They are independent checks.