Email Spoofing Prevention Checklist Form
Complete this checklist to document and review your organization's email spoofing prevention controls. All responses will help ensure robust email security.
Is SPF (Sender Policy Framework) implemented and up to date on all sending domains?
*
Yes
No
Not Applicable
Is DKIM (DomainKeys Identified Mail) configured and regularly validated?
*
Yes
No
Not Applicable
Is DMARC (Domain-based Message Authentication, Reporting, and Conformance) enforced on all domains?
*
Yes
No
Not Applicable
Are all email servers configured to prevent open relaying?
*
Yes
No
Not Applicable
Is outbound email monitored for spoofing attempts?
*
Yes
No
Not Applicable
Are users trained to recognize and report email spoofing attempts?
*
Yes
No
Not Applicable
Is there a documented incident response plan for email spoofing events?
*
Yes
No
Not Applicable
Are email security controls reviewed and tested at least annually?
*
Yes
No
Not Applicable
Are email authentication records (SPF, DKIM, DMARC) monitored for unauthorized changes?
*
Yes
No
Not Applicable
Additional comments or observations
Submit Checklist
Should be Empty: