Understand which email authentication protocols are required by your compliance framework. Each guide maps SPF, DKIM, DMARC, SSL, and other controls to specific framework requirements.
| Framework | SPF | DMARC | DKIM | SSL/TLS | Headers | DNSSEC |
|---|---|---|---|---|---|---|
| SOC 2 | Recommended | Recommended | Recommended | Required | Recommended | Optional |
| HIPAA | Recommended | Required | Recommended | Required | Recommended | Optional |
| GDPR | Recommended | Recommended | Recommended | Required | Recommended | Optional |
| PCI DSS | Recommended | Recommended | Recommended | Required | Required | Optional |
| NIST | Required | Required | Required | Required | Recommended | Required |
| ISO 27001 | Recommended | Recommended | Recommended | Required | Recommended | Optional |
| Cyber Essentials | Recommended | Recommended | Recommended | Required | Recommended | Optional |
| FedRAMP | Required | Required | Required | Required | Required | Required |
| Google & Yahoo 2024 | Required | Required | Required | Required | Optional | Optional |
SOC 2 Type II
How email authentication helps meet SOC 2 Trust Services Criteria for Security and Availability.
Health Insurance Portability and Accountability Act
Protecting PHI in email communications with HIPAA-compliant authentication and encryption.
General Data Protection Regulation
Protecting personal data in email and preventing email-based data breaches under GDPR.
Payment Card Industry Data Security Standard
Email security requirements for organisations handling payment card data under PCI DSS 4.0.
NIST Special Publication 800-177
NIST SP 800-177 Trustworthy Email guidelines for email authentication and security.
ISO/IEC 27001:2022
Email security controls for ISO 27001:2022 ISMS certification and Annex A compliance.
Cyber Essentials (UK)
UK government-backed Cyber Essentials certification and email security best practices.
Federal Risk and Authorization Management Program
Email security requirements for FedRAMP-authorized cloud services in the US federal government.
Google & Yahoo Bulk Sender Requirements
Mandatory email authentication for bulk senders to Gmail and Yahoo Mail.
Run a free scan to see how your domain measures up against compliance requirements. Pro and Agency plans include PDF reports for audit evidence.