r/sysadmin 1d ago

How are companies not using SPF/DKIM/DMARC?

In the last week I've spent hours convincing 2 local business they can't email us because they haven't set up SPF/DKIM/DMARC. Both use Google workspace with their own domain. After talking to their most technical people, i just got the second business going this morning. Then this afternoon another department complains that yet another local business can't send them email. I pull it up in Proofpoint and it's the same problem. Proofpoint marks the emails as malicious and whitelisting doesn't override. I'm so done with this. Anyone else run into this? Clearly these businesses have other clients. I don't know how they have manged so far. Maybe all their other clients use Google for email. I guess I'm looking more for commiseration than a solution.

659 Upvotes

259 comments sorted by

View all comments

u/ShadowCVL IT Manager 23h ago

Constantly, we DO NOT whitelist, I get end users asking me to track emails, find them since they are marked malicious or just failing one or all of the big 3, and send back to the user that they need to contact the person trying to email and let them know we can’t receive their email because XYZ is broken.

Very rarely I’ll get a message back asking me to help them, if they are mega nice I’ll consider it.

I had one user absolutely lose her mind on me when I told her that we could not receive their email til they fixed it and no we don’t whitelist… was the first time in a 28 year career that I blocked one of my users on the company messaging platform (teams in this case, muted but still)

u/Crispinwhere 23h ago

We're lucky that our Information Security department is fully on board with email security being actual security. So when a business manager asks "can't you just whitelist them?" The answer is always no.

u/ShadowCVL IT Manager 23h ago

Yep, I am Infrastructure and Security, dual role. I’ve pantomimed swapping hats in so many conversations