Skip to content

Security & DNS

DMARC

The policy layer that tells receivers what to do with mail failing SPF and DKIM alignment, moved to enforcement in stages so legitimate mail is never lost.

DMARC aggregate report dashboard showing authentication pass rates and spoofing attempts on an operations wall display
SYSTEM ACTIVE
POLICY ENFORCEMENT · DMARC

Capabilities

What we implement

  • Monitoring policy with aggregate reporting
  • Report analysis and sender remediation
  • Staged progression to quarantine then reject
  • Subdomain policy and alignment mode design

Security

How it is hardened

  • Spoofing of the domain becomes materially harder at enforcement
  • Ongoing aggregate report monitoring for new abuse
  • Forensic reporting where the receiver supports it

Architecture

DMARC enforcement rollout

Policy is raised in steps, guided by aggregate reports, so spoofing is blocked without collateral damage to legitimate mail.

  1. 01 · Monitor

    p=nonerua reporting addressBaseline period

    Two to four weeks of reporting establishes who is really sending as the domain.

  2. 02 · Remediate

    Unaligned sender fixesSPF updatesDKIM signing added

    Every legitimate source is brought into alignment before policy moves.

  3. 03 · Quarantine

    p=quarantinepct rampReport review

    Percentage ramp limits exposure while behaviour is confirmed.

  4. 04 · Reject

    p=rejectsp policyOngoing monitoring

    Enforcement with continued report monitoring so new senders are caught early.

FAQ

DMARC questions we are asked

Will DMARC block our own mail?
Not if the rollout is staged. Policy stays at monitoring until reports show every legitimate source authenticating and aligning, which is exactly what the reporting phase is for.
How long does it take to reach reject?
Typically six to twelve weeks for a normal estate, longer where many third-party platforms send on the domain.
What does alignment mean?
The domain in the visible From address must match the domain validated by SPF or DKIM. Authentication can pass while alignment fails, and DMARC only accepts an aligned pass.

Related

Other security & dns platforms

DMARC is referenced to describe engineering capability. All trademarks and product names are the property of their respective owners; no partnership or endorsement is implied.

Ready to scope the work?

Share your environment and objectives. You will get an engineering response covering scope, approach and considerations.