Skip to content
arrow_back
search
ISM-1183 policy ASD Information Security Manual (ISM)

Implement Hard Fail SPF Records for Email Security

Use a strict SPF record to ensure only authorised servers send emails on behalf of the organisation.

record_voice_over

Plain language

This control involves setting up a strict set of rules, called an SPF record, which tells the world which email servers are allowed to send emails on your behalf. It matters because if you don't do this, cybercriminals could send fake emails that look like they come from your organisation, leading to scams, data loss, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation's domains (including subdomains).
policy ASD Information Security Manual (ISM) ISM-1183
priority_high

Why it matters

Without a hard fail SPF record (-all), attackers can send mail spoofing your domain, increasing phishing risk, delivery failures and reputational damage.

settings

Operational notes

Publish SPF with hard fail (-all) where appropriate; review senders, keep within 10 DNS lookups, and update promptly when authorised mail services change.

Mapping detail

Mapping

Direction

Controls