Skip to content
arrow_back
search
ISM-1151 policy ASD Information Security Manual (ISM)

Verify Email Authenticity Using SPF

SPF helps confirm if an email really comes from who it claims to, preventing fake emails.

record_voice_over

Plain language

The 'Verify Email Authenticity Using SPF' control is about ensuring that emails you receive are truly from who they claim to be, rather than from a scammer or hacker impersonating someone else. This matters because fake emails could trick you into revealing sensitive information or downloading harmful software, potentially leading to data breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SPF is used to verify the authenticity of incoming emails.
policy ASD Information Security Manual (ISM) ISM-1151
priority_high

Why it matters

Without SPF checks, attackers can spoof your domain in inbound email, increasing successful phishing, fraud, and data compromise.

settings

Operational notes

Maintain an accurate SPF TXT record for your domain, update it when senders change, and keep DNS lookups within SPF limits.

Mapping detail

Mapping

Direction

Controls