How to Combat Fake Emails - ACSC | Cyber.gov.au

If using the best practice strategy, organisations should explicitly state if a domain does not send emails by specifying v=spf1 -all in the SPF record for that domain. This advises receiving mail servers that there are no authorised sending mail servers for the specified domain, and hence, any emails claiming to be from that domain should be rejected. Warn your users. Ensure users are told of ... ................
................