Cybersecurity GRC 16 items
Email Security Authentication (DMARC/SPF/DKIM) Audit
Audits email authentication and anti-spoofing controls including SPF, DKIM, and DMARC, plus inbound filtering and encryption in transit, aligned to NIST SP 800-177.
RFC 7489RFC 7208RFC 6376NIST 800-177
Free PDF · enter your email to download.
SPF Configuration
- Is an SPF record published for every sending domain? *
- Does the SPF record end with a hard fail (-all) or soft fail (~all) qualifier? *
- Is the SPF record within the 10 DNS-lookup limit? *
- Are parked/non-sending domains configured with a null SPF (v=spf1 -all)?
DKIM Configuration
- Is DKIM signing enabled for all outbound mail streams? *
- Are DKIM keys at least 2048-bit RSA? *
- Are DKIM keys rotated on a defined schedule?
- Are third-party senders configured to DKIM-sign on behalf of your domain?
DMARC Configuration
- Is a DMARC record published for all sending domains? *
- Is the DMARC policy set to quarantine or reject (not p=none)? *
- Are DMARC aggregate (rua) reports collected and monitored? *
- Has alignment been verified so legitimate mail passes before enforcing reject? *
Inbound Protection
- Is inbound DMARC evaluation enforced on the mail gateway? *
- Is anti-phishing and anti-spoofing filtering enabled on inbound mail? *
- Is opportunistic or enforced TLS enabled for mail in transit? *
- Are external-sender warning banners applied to inbound email?
Download the full Email Security Authentication (DMARC/SPF/DKIM) Audit checklist
Get it as a clean, printable PDF — free.
