We checked 101 South Coast business domains this morning. Half can be impersonated by anyone with an email account.
A 20-minute, step-by-step walkthrough for setting up SPF, DKIM and DMARC on your own domain, written for a Westport tailor but usable by any small business. Every step performed and documented on a real domain today.

A tailor's email is quiet money. The quote you send a bride in April books the fitting in May. The "your suit is ready" note gets the garment off your rack and the balance into your till. A Westport tailor doing wedding-season alterations might send a few hundred emails a season and never once wonder how they get delivered.
Here is why you should wonder, and then a 20-minute procedure to settle the question for good. I performed every step below on a real domain this morning, and I'll show you the actual results as we go.
What we measured today#
Since June, Avalon has audited local business websites across Fall River, Somerset, Fairhaven, New Bedford and Providence. This morning I took the 101 business domains collected in those audits and checked each one for the two public email ID records anyone can look up: SPF (which lists who is allowed to send mail for your domain) and DMARC (which tells Gmail and Yahoo what to do with mail that fails the check).
These businesses are not named here and never will be; they didn't ask to be graded. The aggregate picture is the point:
| Record | Domains with it | Share of 101 |
|---|---|---|
| SPF | 69 | 68% |
| DMARC (any policy) | 51 | 50% |
| DMARC that actually blocks impostors | 12 | 12% |
What we could NOT measure: DKIM, the third record, is only visible if you know a domain's private selector name, so we make no claim about how many of the 101 have it. Not measured means not claimed.
The plain-English version: for half the business domains we checked, anyone with a laptop can send email that says it is from that business, and the big inboxes have been given no instruction to stop it. That is how a scammer emails your bridal client "from" your shop about a deposit. And since February 2024, Gmail and Yahoo have also been progressively tightening delivery for unauthenticated senders, so the same gap that lets impostors in also pushes your real quotes toward spam.
Sending properly authenticated messages helps us to better identify and block billions of malicious messages and declutter our users' inboxes.
Read that from the other side of the counter: if your messages are not properly authenticated, you are in the pile being identified and blocked.
The 20-minute walkthrough#
You need: the login for wherever you bought your domain (GoDaddy, Squarespace, Namecheap, whoever), and 20 minutes. Everything below is free. If your email address ends in @gmail.com or @comcast.net rather than @yourshop.com, this article is not your problem yet; the records below belong to domain owners.
I ran each step on Avalon's own domain this morning so you can see what "done" looks like.
Step 1: Find out who sends your mail (2 minutes)#
Your email provider is whoever hosts your inbox: Microsoft 365, Google Workspace, or your registrar's bundled email. Check the bill or the login page you use for mail. Write it down; steps 3 and 4 need it.
Step 2: Test where you stand (3 minutes)#
Send an email from your business address to a Gmail address you control. Open it in Gmail, click the three-dot menu, choose Show original. The top of that page gives verdicts for SPF, DKIM and DMARC. Three PASSes and you can close this tab and go press a suit. Anything else, keep going.
Step 3: Look up your records the way I looked up those 101 (3 minutes)#
Put your domain into Google's free Admin Toolbox Check MX page. It flags missing SPF and DMARC in plain language. This is the same public lookup I used for the numbers above; you are simply auditing yourself before someone else does.
Here is Avalon's own SPF record, exactly as the public lookup returns it today:
v=spf1 include:dc-aa8e722993._spfm.avalonpartner.com ~all
Yours will look different; the shape is what matters. v=spf1 declares the record, the include: names your provider, and the ~all at the end means "treat everyone else with suspicion."
Step 4: Add SPF if it's missing (5 minutes)#
Log in at your registrar, find DNS settings (sometimes "Manage DNS" or "DNS records"), and add a TXT record on your bare domain with the value your provider documents. The two most common:
Microsoft 365: v=spf1 include:spf.protection.outlook.com -all
Google Workspace: v=spf1 include:_spf.google.com ~all
One rule: a domain gets exactly ONE SPF record. If a record starting with v=spf1 already exists, edit it; never add a second.
Step 5: Switch on DKIM at your provider (5 minutes)#
DKIM is a cryptographic signature your provider stamps on every outgoing message. You don't write this record yourself; you switch it on. In Google Workspace it lives under Admin console → Apps → Google Workspace → Gmail → Authenticate email. In Microsoft 365 it's in the Defender portal under Email authentication settings → DKIM. Each gives you one or two records to copy into the same registrar DNS page from step 4, then you return and click enable.
Step 6: Add a starter DMARC record (2 minutes)#
Back at your registrar's DNS page, add a TXT record with the host name _dmarc and this value, with your own address in it:
v=DMARC1; p=none; rua=mailto:you@yourdomain.com
p=none changes nothing about delivery yet. It puts you on the scoreboard, satisfies the inbox providers' minimum requirement, and starts emailing you reports about who is sending mail as your domain. After a few clean weeks, tighten to p=quarantine. Avalon's live record, for reference, is at that stage today:
v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net;
Step 7: Re-run the test (2 minutes, tomorrow)#
DNS changes take up to a day to spread. Tomorrow, repeat step 2. The goal is three PASSes on Show original.
What this means for a Westport tailor on Monday#
Wedding season is your revenue spike, and it runs on email to people who have never met you: brides, grooms, mothers of, best men. Gmail has no history with them and you, so it leans entirely on these records when deciding whether your quote reaches the inbox. A tailor whose domain shows two FAILs isn't losing email; they're losing fittings and never seeing the bounce.
Monday, before the first hem: run step 2. It costs ten minutes and tells you the truth. If you get three PASSes, you're ahead of half the South Coast businesses we measured, literally.
If you'd rather spend those twenty minutes on a lapel than on a registrar login screen, that is a sound business decision too. This is the kind of thing we finish in an afternoon, reports and follow-up tightening included.
Joshua Amado · Avalon Partner · 774.559.8992 · Joshua.Amado@AvalonPartner.com
Filed under
Want help putting this into practice?
Avalon Partner helps Fall River and South Coast businesses fix the gaps that cost them leads. Call 774.559.8992 or email Joshua.Amado@AvalonPartner.com.


