← Digital Channel and Technical Security

CYB-08 · Cyber security

Email authentication — SPF, DKIM, and DMARC (p=quarantine or reject) configured on all sending domains

Business Email Compromise (BEC) is the highest-frequency financial fraud vector against SA insurance brokers. All email-sending domains must have: SPF (hard fail -all), DKIM signing, and DMARC at minimum p=quarantine. This prevents domain spoofing and is a primary BEC defence. Missing DMARC p=none provides zero protection.

Critical priority

Trigger

When this rule fires

SPF record absent or using soft-fail only (~all); DKIM not configured on primary sending domain; DMARC absent or set to p=none

Applicability gate

Confirm the entity's role before treating this as a duty

This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.

  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.

Citation

Mapped source

This control maps to the public instruments below. The mapping does not establish entity applicability.

Section
Joint Standard 2 of 2024 / POPIA s.19 / BEC risk
Legislation
  • Joint Standard 2 of 2024
  • POPIA s.19

Remediation

How to close the gap

Configure SPF with -all hard fail. Enable DKIM signing on all outbound mail. Set DMARC to p=quarantine with rua/ruf reporting addresses. Move to p=reject once reporting confirms no legitimate mail is failing. Monitor DMARC reports weekly.

Evidence required

Evidence to prepare if this control applies

  • SPF DNS record (dig/nslookup output)
  • DKIM public key DNS record
  • DMARC DNS record (_dmarc.domain.co.za TXT)
  • DMARC aggregate reports (last 30 days)
  • MXToolbox or DMARC Analyzer report

Automated assessment

Verified by the Provantis cyber scanner. Machine checks performed:

  • SPF_CONFIGURED
  • SPF_HARD_FAIL
  • DKIM_CONFIGURED
  • DMARC_CONFIGURED
  • DMARC_ENFORCED