Email Authentication

Publish it. Prove it. Enforce it.

Email authentication is the only control that decides whether a stranger can put your company's name in the From field and have it delivered. Three DNS records carry it, and publishing all three takes an afternoon. Knowing which of your senders those records actually authorize, which of your mail survives a forward, and whether any receiver is under instruction to act on a failure takes a method. This course is that method.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 8 CPE Credits

What you'll be able to do

Read a receiver's verdict from a message header and say which domain each result belonged to
Design an authorization record from an inventory of what the organization actually sends, and count its cost against the lookup limit honestly
Get every third-party platform signing as your domain rather than as their own, and rotate a key without failing mail already in flight
Turn a month of aggregate reports into a sender list, and tell a spoofing campaign apart from a sender that broke
Take a domain to an enforcing policy on evidence, with a rehearsal, a rollback and exit conditions decided in advance
Audit any domain's posture in ten minutes and hand back the exact records that would fix it
Operate the result with a monthly check that catches drift arriving from suppliers and departments who never told you
ARC405 | Premium tier | 6 modules across 4 phases | 6–8 hours at your own pace | 8 CPE credits | Updated July 2026
Course Agenda View Course ModulesHide Course Modules

Course overview

Most domains did not have their authentication designed. It accumulated. Someone published a record during a mail migration, a marketing platform's onboarding wizard asked for an include and got one, a consultant added a policy during an audit and set it to monitoring so nothing would break, and everybody moved on. Every record returns a valid answer when you query it, and the domain is still spoofable, because a record that parses is a different thing from a record that authorizes the right senders and a policy anybody acts on.

Two sender identities on every message, and why a pass can belong to a domain your recipient never sees
The lookup limit that turns a working record into a permanent failure with no error anywhere
Aggregate reports as the only view of your domain that is not self-reported
A staged path to enforcement built on the 2026 standard, not the deprecated tag every older guide still teaches

By the end you can answer the question this subject makes surprisingly hard: what is my domain actually sending, and would I know if that changed.

Who this course is for

Anyone answerable for a domain's mail. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never added a TXT record or have been maintaining these for years.

Security engineers and Microsoft 365 or Google Workspace administrators who own the domain's mail
Analysts who keep finding authentication headers in phishing investigations and cannot yet read them at speed
Anybody who has inherited a domain sitting at monitoring and needs to know what it would take to move it
Consultants and assessors who need to read any domain's posture in ten minutes and hand back the records that fix it

What you'll learn

Read a receiver's verdict from a message header and say which domain each result belonged to
Design an authorization record from an inventory of what your organization actually sends, and count its cost honestly
Get every platform on that inventory signing as your domain rather than as their own, and rotate a key without breaking mail in flight
Turn a month of aggregate reports into a sender list, and tell a spoofing campaign apart from a sender that broke
Take a domain to an enforcing policy on evidence, with a rehearsal, a rollback and a definition of done
Audit any domain's posture in ten minutes and hand back the exact records that would fix it

Key course takeaways

A sender inventory with an owner and an authentication state per row, which is the artifact every later decision depends on
A record set you can publish, with the reasoning written beside it so a future reviewer can tell what was deliberate
A rollout sequence with exit conditions, a rehearsal step and a rollback, so enforcement is a decision rather than a leap
A twenty-minute monthly check that catches the drift arriving from suppliers and departments who never told you
A ten-minute audit that works on your estate, a supplier's domain, or whatever sent this morning's invoice

Things you need to know

What are the prerequisites for this course?

None beyond having added a DNS record at some point, and the course explains what a TXT record is at the point you first need one. No cryptography background is assumed: signing and verification are built from first principles.

Do I need a lab or a license to follow along?

No. Every record in this subject is public, so the queries work against any domain from any machine, including your own. Where the course covers platform configuration it gives the Microsoft 365 and Google Workspace paths, and the reasoning stands on its own without a tenant.

Is this course current?

The DMARC specification was replaced in May 2026 by RFC 9989, 9990 and 9991. Three tags were removed, three added, and the method receivers use to find a policy changed. This course is built on that standard rather than the one it replaced, which is the main respect in which it differs from most material on this subject.

What about the parts that are still moving?

The chain-of-custody mechanism is proposed for retirement and a successor to the signing standard is in working group drafts. The course covers both at their actual status, says plainly that neither requires action, and tells you how to check whether that has changed.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Records, headers, reports and scenarios are illustrative and constructed for teaching. Verify against your own domain and against the current specifications before relying on any specific behavior, and treat your own aggregate reports as authoritative over any document, including this one.

Ridgeline Cyber is not affiliated with Microsoft, Google or any certificate authority. Product names are used descriptively.

Version and changelog

Version 1.0 · July 2026

Initial release as ARC405, replacing the earlier Email Authentication short course. Six modules covering the authentication decision, SPF, DKIM, DMARC and evidence, reaching enforcement, and operating the result, with an operational reference and a references module.

Built on RFC 9989, 9990 and 9991. Research-gated against the specifications, Microsoft Learn, Google Workspace documentation and the current IETF drafts.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

Requires 80% course completion. One random scenario per attempt. Certificate issued on pass.