Email Authentication
Publish it. Prove it. Enforce it.
Email authentication is the only control that decides whether a stranger can put your company's name in the From field and have it delivered. Three DNS records carry it, and publishing all three takes an afternoon. Knowing which of your senders those records actually authorize, which of your mail survives a forward, and whether any receiver is under instruction to act on a failure takes a method. This course is that method.
What you'll be able to do
Course overview
Most domains did not have their authentication designed. It accumulated. Someone published a record during a mail migration, a marketing platform's onboarding wizard asked for an include and got one, a consultant added a policy during an audit and set it to monitoring so nothing would break, and everybody moved on. Every record returns a valid answer when you query it, and the domain is still spoofable, because a record that parses is a different thing from a record that authorizes the right senders and a policy anybody acts on.
By the end you can answer the question this subject makes surprisingly hard: what is my domain actually sending, and would I know if that changed.
Who this course is for
Anyone answerable for a domain's mail. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never added a TXT record or have been maintaining these for years.
What you'll learn
Key course takeaways
Things you need to know
What are the prerequisites for this course?
None beyond having added a DNS record at some point, and the course explains what a TXT record is at the point you first need one. No cryptography background is assumed: signing and verification are built from first principles.
Do I need a lab or a license to follow along?
No. Every record in this subject is public, so the queries work against any domain from any machine, including your own. Where the course covers platform configuration it gives the Microsoft 365 and Google Workspace paths, and the reasoning stands on its own without a tenant.
Is this course current?
The DMARC specification was replaced in May 2026 by RFC 9989, 9990 and 9991. Three tags were removed, three added, and the method receivers use to find a policy changed. This course is built on that standard rather than the one it replaced, which is the main respect in which it differs from most material on this subject.
What about the parts that are still moving?
The chain-of-custody mechanism is proposed for retirement and a successor to the signing standard is in working group drafts. The course covers both at their actual status, says plainly that neither requires action, and tells you how to check whether that has changed.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
Records, headers, reports and scenarios are illustrative and constructed for teaching. Verify against your own domain and against the current specifications before relying on any specific behavior, and treat your own aggregate reports as authoritative over any document, including this one.
Ridgeline Cyber is not affiliated with Microsoft, Google or any certificate authority. Product names are used descriptively.
Version and changelog
Version 1.0 · July 2026
Initial release as ARC405, replacing the earlier Email Authentication short course. Six modules covering the authentication decision, SPF, DKIM, DMARC and evidence, reaching enforcement, and operating the result, with an operational reference and a references module.
Built on RFC 9989, 9990 and 9991. Research-gated against the specifications, Microsoft Learn, Google Workspace documentation and the current IETF drafts.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.