Email Authentication and DMARC Enforcement
Read the verdict. Authorize the senders. Reach reject on evidence.
Three DNS records decide whether a stranger can send as your domain and be delivered. Publishing them takes an afternoon. Reading what receivers concluded, finding every system sending as you, reaching reject without breaking mail, and keeping it there is the course. Built on the 2026 DMARC standard.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Course Orientation
What Email Authentication and DMARC Enforcement teaches: how a receiver reaches a verdict on a message, what SPF and DKIM each actually claim, why alignment decides whether either claim counts, and how to take a domain to enforcement without breaking legitimate mail. Built on the 2026 DMARC standard. Start here.
Phase 1: The Decision
How a receiver reaches a verdict on a message. The two sender identities every message carries and which one a person sees, what SPF and DKIM each actually claim, reading the header a receiver writes its findings into, the comparison that decides whether any pass counts, what a receiver is free to do with a policy, and the spoofing that passes every check honestly.
Show 7 lessonsHide lessons
Phase 2: The Two Claims
The record that authorizes servers to send using your domain. How a record is read and evaluated, the hard limit on DNS lookups that breaks working records silently, what an include chain actually delegates, designing a record from a real sender inventory, verifying it, and where SPF stops being able to help.
The record that travels with the message, built and operated: a signature dissected and verified by hand, keys generated and published, Microsoft 365 and Google signing as your domain end to end, a real failure diagnosed to its owner, rotation with the commands, and the replay case worked.
Phase 3: The Policy
The record that ties the other two together and the reports that finally show what your domain sends. The 2026 tag set including what was added and removed, how a receiver discovers which policy applies, publishing a monitoring record, and reading aggregate reports as evidence.
Phase 4: Enforcement and Operations
Taking a domain from monitoring to an enforcing policy without losing legitimate mail. The order of operations, using test mode as a rehearsal, making the change safely, handling subdomains and senders that cannot authenticate, the forwarding problem, and what to do when something breaks.
Keeping an enforcing domain enforcing. The drift that arrives without anybody making a change, reading reports as a monthly operation, the domain audit as a repeatable deliverable, the transport security records in the same zone, BIMI, and an honest account of where the standards are heading.
Phase 0: Course Resources
What each check proves, the record syntax and its limits, reading a report, and the failures that are not yours.
Ordered procedures for inventorying senders, reaching enforcement, onboarding a platform, and diagnosing a delivery failure.
Show 4 lessonsHide lessons
Four cases reasoned end to end, including the forgery that passed every check and the outage nobody had changed anything to cause.
A domain you control, a few DNS records, and the checks that make the practice real.
Every record format, query, command, tag value and check from the Email Authentication and DMARC Enforcement course in one place, organized by task and linked back to the section that explains when not to use it.
Show 1 lessonHide lessons
Where to check whether anything in this course has changed, the standards that were rewritten in 2026, the drafts still in motion, and the authoritative source for each class of fact. Organized by the question you arrived with rather than by source type.
Course Completion
Email Authentication and DMARC Enforcement end-of-course exam: invoice fraud where SPF, DKIM and DMARC all passed correctly, a supplier about to be wrongly accused, and what the investigation reveals about your own outbound posture.
Show 1 lessonHide lessons
Course overview
Most domains did not have their authentication designed. It accumulated. Someone published a record during a mail migration, a marketing platform's onboarding wizard asked for an include and got one, a consultant added a policy during an audit and set it to monitoring so nothing would break, and everybody moved on. Every record returns a valid answer when you query it, and the domain is still spoofable, because a record that parses is a different thing from a record that authorizes the right senders and a policy anybody acts on.
By the end you can answer the question this subject makes surprisingly hard: what is my domain actually sending, and would I know if that changed.
How this course works
SPF, DKIM and DMARC are three records that produce one decision at the receiving mail server. This course runs the same loop for each of them, because most estates have all three published and none of them enforcing.
1. Read what the receiver actually does. The decision is made by somebody else's server against your published record. Reason from their evaluation, not from your intent.
2. Publish the record and read it back. An SPF record costing eleven DNS lookups against a limit of ten is broken with no mail flowing and no error anywhere.
3. Turn on reporting before enforcement. DMARC aggregate reports tell you who is sending as you. Moving to reject without reading them is how a legitimate sender gets blocked on a Monday morning.
4. Move the policy one step at a time. None to quarantine to reject, rehearsed first with the test flag the 2026 standard added and scoped by name rather than by percentage, with a reason to move recorded rather than a calendar date.
5. Operate it as configuration that drifts. A supplier restructures an include, a department buys a tool, a contract ends with the keys still published, and the record that was correct last quarter now authorizes something nobody told you about. A monthly diff and a ledger catch it; a ten-minute audit reads any other domain the same way.
What this course assumes
No minimum experience and no prerequisite course. DNS records, mail flow and the difference between the envelope sender and the visible From address are explained where they first matter.
What makes it go faster: access to your own DNS and a mailbox you can send test mail from. Neither is required, and every record in the course can be inspected against public domains.
What this course does not cover: mail server administration, spam filtering, and phishing investigation. This is the authentication layer and the policy decision on top of it.
Who this course is for
Anyone answerable for a domain's mail. There is no minimum experience and no gatekeeping: every concept is explained at first use, so you can start here whether you have never added a TXT record or have been maintaining these for years.
What you'll learn
Key course takeaways
Course Resources - what comes with the modules
Every course carries a resources phase built for that course and no other. It is the part subscribers keep going back to long after they have read the modules once.
Things you need to know
What are the prerequisites for this course?
None beyond having added a DNS record at some point, and the course explains what a TXT record is at the point you first need one. No cryptography background is assumed: signing and verification are built from first principles.
Do I need a lab or a license to follow along?
No. Every record in this subject is public, so the queries work against any domain from any machine, including your own. Where the course covers platform configuration it gives the Microsoft 365 and Google Workspace paths, and the reasoning stands on its own without a tenant.
Is this course current?
The DMARC specification was replaced in May 2026 by RFC 9989, 9990 and 9991. Three tags were removed, three added, and the method receivers use to find a policy changed. This course is built on that standard rather than the one it replaced, which is the main respect in which it differs from most material on this subject.
What about the parts that are still moving?
The chain-of-custody mechanism is proposed for retirement and a successor to the signing standard is in working group drafts. The course covers both at their actual status, says plainly that neither requires action, and tells you how to check whether that has changed.
Usage rights and disclaimer
Course materials are licensed for your individual use. You may apply everything you build here in your own environment and in client work. You may not redistribute the course content itself or resell it as training.
Records, headers, reports and scenarios are illustrative and constructed for teaching. Verify against your own domain and against the current specifications before relying on any specific behavior, and treat your own aggregate reports as authoritative over any document, including this one.
Ridgeline Cyber is not affiliated with Microsoft, Google or any certificate authority. Product names are used descriptively.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.