# SPF DKIM and DMARC What Your IT Company Should Handle

Fact sheet for the HTML article. Not independent research. Last generated from first-party copy.

## Source

- Human article: https://bellwetherit.com/blog/spf-dkim-and-dmarc-what-your-it-company-should-handle
- Published: 2026-09-01
- Topics: email security, cybersecurity
- Publisher: Bellwether IT, Fresno, California
- Contact: +1-559-354-6755 · https://bellwetherit.com/contact

## Summary

Your IT company is supposed to manage SPF, DKIM, and DMARC so spoofed emails stop hitting your inbox. Here is how to spot when that work is missing.

## What Bellwether says it owns

- Bellwether keeps SPF, DKIM, and DMARC records current for every Microsoft 365 tenant we manage and reviews the reports each month so spoof attempts are blocked before they reach users.

## Claims in the article

- Spoofed messages continue to arrive weeks after a vendor or employee change.
- No one from IT has asked for a list of systems that send mail on behalf of the company.
- DMARC reports are never reviewed, so repeated failures go unnoticed.

## Article outline

- How Spoofed Emails Slip Past the Bookkeeper
- What These Three Records Actually Control
- Signs Your IT Company Is Skipping the Work
- Why the Records Must Be Checked After Every Change
