Email Authentication and DMARC Enforcement

Read the verdict. Authorize the senders. Reach reject on evidence.

Three DNS records decide whether a stranger can send as your domain and be delivered. Publishing them takes an afternoon. Reading what receivers concluded, finding every system sending as you, reaching reject without breaking mail, and keeping it there is the course. Built on the 2026 DMARC standard.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 8 CPE Credits

What you'll be able to do

✓Read a receiver's verdict from a message header and say which domain each result belonged to
✓Design an authorization record from an inventory of what the organization actually sends, and count its cost against the lookup limit honestly
✓Get every third-party platform signing as your domain rather than as their own, and rotate a key without failing mail already in flight
✓Turn a month of aggregate reports into a sender list, and tell a spoofing campaign apart from a sender that broke
✓Take a domain to an enforcing policy on evidence, with a rehearsal, a rollback and exit conditions decided in advance
✓Audit any domain's posture in ten minutes and hand back the exact records that would fix it
✓Operate the result with a monthly check that catches drift arriving from suppliers and departments who never told you
ARC405 | Premium tier | 6 modules across 4 phases | 6–8 hours at your own pace | 8 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Course Orientation

Module 0Course OrientationCourse Preview

What Email Authentication and DMARC Enforcement teaches: how a receiver reaches a verdict on a message, what SPF and DKIM each actually claim, why alignment decides whether either claim counts, and how to take a domain to enforcement without breaking legitimate mail. Built on the 2026 DMARC standard. Start here.

Phase 1: The Decision

Module 1The Authentication Decision

How a receiver reaches a verdict on a message. The two sender identities every message carries and which one a person sees, what SPF and DKIM each actually claim, reading the header a receiver writes its findings into, the comparison that decides whether any pass counts, what a receiver is free to do with a policy, and the spoofing that passes every check honestly.

Show 7 lessonsHide lessons
  1. 1.11.1 Envelope and Header Sender Identities
  2. 1.21.2 SPF, DKIM and DMARC: What Each Check Proves
  3. 1.31.3 The Authentication-Results Header
  4. 1.41.4 Identifier Alignment
  5. 1.51.5 Policy Values and Receiver Handling
  6. 1.61.6 Coverage Limits and Complementary Controls
  7. 1.7Module Summary and Knowledge Check

Phase 2: The Two Claims

Module 2SPF: Authorizing Your Senders

The record that authorizes servers to send using your domain. How a record is read and evaluated, the hard limit on DNS lookups that breaks working records silently, what an include chain actually delegates, designing a record from a real sender inventory, verifying it, and where SPF stops being able to help.

Show 7 lessonsHide lessons
  1. 2.12.1 SPF Record Syntax and Evaluation Order
  2. 2.22.2 The DNS Lookup Limit
  3. 2.32.3 Include Chains and Inherited Senders
  4. 2.42.4 Record Design from a Sender Inventory
  5. 2.52.5 Publishing and Verification
  6. 2.62.6 SPF Coverage Limits
  7. 2.7Module Summary and Knowledge Check
Module 3DKIM: The Signature That Travels

The record that travels with the message, built and operated: a signature dissected and verified by hand, keys generated and published, Microsoft 365 and Google signing as your domain end to end, a real failure diagnosed to its owner, rotation with the commands, and the replay case worked.

Show 7 lessonsHide lessons
  1. 3.13.1 What a Signature Commits To
  2. 3.23.2 Selectors and Keys
  3. 3.33.3 Getting Your Platforms to Sign as You
  4. 3.43.4 What Breaks a Signature
  5. 3.53.5 Key Rotation
  6. 3.63.6 Replay, and Where DKIM Ends
  7. 3.7Module Summary and Knowledge Check

Phase 3: The Policy

Module 4DMARC: Policy and Evidence

The record that ties the other two together and the reports that finally show what your domain sends. The 2026 tag set including what was added and removed, how a receiver discovers which policy applies, publishing a monitoring record, and reading aggregate reports as evidence.

Show 7 lessonsHide lessons
  1. 4.14.1 The Record and Its Tags
  2. 4.24.2 Policy Discovery
  3. 4.34.3 Publishing Your First Record
  4. 4.44.4 Reading Aggregate Reports
  5. 4.54.5 Failure Reports
  6. 4.64.6 From Reports to Decisions
  7. 4.7Module Summary and Knowledge Check

Phase 4: Enforcement and Operations

Module 5Reaching Enforcement

Taking a domain from monitoring to an enforcing policy without losing legitimate mail. The order of operations, using test mode as a rehearsal, making the change safely, handling subdomains and senders that cannot authenticate, the forwarding problem, and what to do when something breaks.

Show 7 lessonsHide lessons
  1. 5.15.1 The Sequence
  2. 5.25.2 The Rehearsal
  3. 5.35.3 Making the Move
  4. 5.45.4 Subdomains and the Senders That Cannot Authenticate
  5. 5.55.5 Forwarding and Mailing Lists
  6. 5.65.6 When It Goes Wrong
  7. 5.7Module Summary and Knowledge Check
Module 6Operate and Audit

Keeping an enforcing domain enforcing. The drift that arrives without anybody making a change, reading reports as a monthly operation, the domain audit as a repeatable deliverable, the transport security records in the same zone, BIMI, and an honest account of where the standards are heading.

Show 7 lessonsHide lessons
  1. 6.16.1 Drift
  2. 6.26.2 Reading Reports as an Operation
  3. 6.36.3 The Domain Audit
  4. 6.46.4 Transport Security
  5. 6.56.5 BIMI
  6. 6.66.6 The Honest Edge
  7. 6.7Module Summary and Knowledge Check

Phase 0: Course Resources

ResourcesCheatsheets

What each check proves, the record syntax and its limits, reading a report, and the failures that are not yours.

Show 4 lessonsHide lessons
  1. 1What Each Check Actually Proves
  2. 2The Records You Publish
  3. 3DMARC, Reports and Reaching Enforcement
  4. 4Operating It, and the Failures That Are Not Yours
ResourcesCookbooks

Ordered procedures for inventorying senders, reaching enforcement, onboarding a platform, and diagnosing a delivery failure.

Show 4 lessonsHide lessons
  1. 1Inventorying Who Sends as You
  2. 2Getting to Reject
  3. 3Onboarding a New Sending Platform
  4. 4Diagnosing Mail That Stopped Arriving
ResourcesWalkthroughs

Four cases reasoned end to end, including the forgery that passed every check and the outage nobody had changed anything to cause.

Show 4 lessonsHide lessons
  1. 1The Invoice That Passed Every Check
  2. 2The Outage Nobody Had Caused
  3. 3The Sender That Only Mails in January
  4. 4The Signature a Security Tool Broke
ResourcesPlayground

A domain you control, a few DNS records, and the checks that make the practice real.

ResourcesOperational Reference

Every record format, query, command, tag value and check from the Email Authentication and DMARC Enforcement course in one place, organized by task and linked back to the section that explains when not to use it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

Where to check whether anything in this course has changed, the standards that were rewritten in 2026, the drafts still in motion, and the authoritative source for each class of fact. Organized by the question you arrived with rather than by source type.

Course Completion

CompletionCourse Exam

Email Authentication and DMARC Enforcement end-of-course exam: invoice fraud where SPF, DKIM and DMARC all passed correctly, a supplier about to be wrongly accused, and what the investigation reveals about your own outbound posture.

Show 1 lessonHide lessons
  1. 1Course Completion. Email Authentication and DMARC Enforcement

Course overview

Most domains did not have their authentication designed. It accumulated. Someone published a record during a mail migration, a marketing platform's onboarding wizard asked for an include and got one, a consultant added a policy during an audit and set it to monitoring so nothing would break, and everybody moved on. Every record returns a valid answer when you query it, and the domain is still spoofable, because a record that parses is a different thing from a record that authorizes the right senders and a policy anybody acts on.

✓ Two sender identities on every message, and why a pass can belong to a domain your recipient never sees
✓ The lookup limit that turns a working record into a permanent failure with no error anywhere
✓ Aggregate reports as the only view of your domain that is not self-reported
✓ A staged path to enforcement built on the 2026 standard, not the deprecated tag every older guide still teaches

By the end you can answer the question this subject makes surprisingly hard: what is my domain actually sending, and would I know if that changed.

How this course works

SPF, DKIM and DMARC are three records that produce one decision at the receiving mail server. This course runs the same loop for each of them, because most estates have all three published and none of them enforcing.

1. Read what the receiver actually does. The decision is made by somebody else's server against your published record. Reason from their evaluation, not from your intent.

2. Publish the record and read it back. An SPF record costing eleven DNS lookups against a limit of ten is broken with no mail flowing and no error anywhere.

3. Turn on reporting before enforcement. DMARC aggregate reports tell you who is sending as you. Moving to reject without reading them is how a legitimate sender gets blocked on a Monday morning.

4. Move the policy one step at a time. None to quarantine to reject, rehearsed first with the test flag the 2026 standard added and scoped by name rather than by percentage, with a reason to move recorded rather than a calendar date.

5. Operate it as configuration that drifts. A supplier restructures an include, a department buys a tool, a contract ends with the keys still published, and the record that was correct last quarter now authorizes something nobody told you about. A monthly diff and a ledger catch it; a ten-minute audit reads any other domain the same way.

What this course assumes

No minimum experience and no prerequisite course. DNS records, mail flow and the difference between the envelope sender and the visible From address are explained where they first matter.

What makes it go faster: access to your own DNS and a mailbox you can send test mail from. Neither is required, and every record in the course can be inspected against public domains.

What this course does not cover: mail server administration, spam filtering, and phishing investigation. This is the authentication layer and the policy decision on top of it.

Who this course is for

Anyone answerable for a domain's mail. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never added a TXT record or have been maintaining these for years.

✓ Security engineers and Microsoft 365 or Google Workspace administrators who own the domain's mail
✓ Analysts who keep finding authentication headers in phishing investigations and cannot yet read them at speed
✓ Anybody who has inherited a domain sitting at monitoring and needs to know what it would take to move it
✓ Consultants and assessors who need to read any domain's posture in ten minutes and hand back the records that fix it

What you'll learn

✓ Read a receiver's verdict from a message header and say which domain each result belonged to
✓ Design an authorization record from an inventory of what your organization actually sends, and count its cost honestly
✓ Get every platform on that inventory signing as your domain rather than as their own, and rotate a key without breaking mail in flight
✓ Turn a month of aggregate reports into a sender list, and tell a spoofing campaign apart from a sender that broke
✓ Take a domain to an enforcing policy on evidence, with a rehearsal, a rollback and a definition of done
✓ Audit any domain's posture in ten minutes and hand back the exact records that would fix it

Key course takeaways

✓ A sender inventory with an owner and an authentication state per row, which is the artifact every later decision depends on
✓ A record set you can publish, with the reasoning written beside it so a future reviewer can tell what was deliberate
✓ A rollout sequence with exit conditions, a rehearsal step and a rollback, so enforcement is a decision rather than a leap
✓ A monthly check, scripted, that catches the drift arriving from suppliers and departments who never told you
✓ A ten-minute audit that works on your estate, a supplier's domain, or whatever sent this morning's invoice

Course Resources - what comes with the modules

Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.

✓ Walkthroughs work a mail failure back to the record that caused it: the invoice that passed every check, the outage nobody had caused, the sender that only mails in January, and the signature a security tool broke.
✓ A cookbook for the jobs this skill is actually hired for: inventorying who sends as you, getting to reject without breaking mail, onboarding a new sending platform, and diagnosing mail that stopped arriving.
✓ A command cheatsheet organized by what each check proves, what you publish, and which failures are not yours to fix.
✓ An operational reference with the record syntax, the lookup limits and the report fields, consolidated.
✓ A playground that costs a few dollars a year: a domain you own and do not care about, so you can publish a bad record, exceed the lookup limit and pull a selector mid-flight to see what happens.
✓ A references module built on the current RFCs and the vendor documentation, because this is a standards discipline and the standards moved recently.

Things you need to know

What are the prerequisites for this course?

None beyond having added a DNS record at some point, and the course explains what a TXT record is at the point you first need one. No cryptography background is assumed: signing and verification are built from first principles.

Do I need a lab or a license to follow along?

No. Every record in this subject is public, so the queries work against any domain from any machine, including your own. Where the course covers platform configuration it gives the Microsoft 365 and Google Workspace paths, and the reasoning stands on its own without a tenant.

Is this course current?

The DMARC specification was replaced in May 2026 by RFC 9989, 9990 and 9991. Three tags were removed, three added, and the method receivers use to find a policy changed. This course is built on that standard rather than the one it replaced, which is the main respect in which it differs from most material on this subject.

What about the parts that are still moving?

The chain-of-custody mechanism is proposed for retirement and a successor to the signing standard is in working group drafts. The course covers both at their actual status, says plainly that neither requires action, and tells you how to check whether that has changed.

Usage rights and disclaimer

Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.

Records, headers, reports and scenarios are illustrative and constructed for teaching. Verify against your own domain and against the current specifications before relying on any specific behavior, and treat your own aggregate reports as authoritative over any document, including this one.

Ridgeline Cyber is not affiliated with Microsoft, Google or any certificate authority. Product names are used descriptively.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.

40minutes
3phases
100points
1scenario
Take End of Course Exam

One random scenario per attempt. Certificate issued on pass.