DMARC for small businesses: a concise, practical checklist to stop domain spoofing and improve deliverability

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
DMARC, SPF and DKIM help receiving mail systems verify email that claims to come from your domain. This concise buyer-side checklist explains what to check, why bulk-sender rules make it more urgent and what to ask your IT provider before moving from monitoring to enforcement.
For a small business, email is both a daily essential and a common route for fraud. A criminal can make a message appear to come from your domain even though your business never sent it. A customer or supplier may then trust a payment request, password prompt or malicious link because the sender looks familiar.
DMARC helps receiving mail systems decide what to do when an email claiming to come from your domain fails authentication. It works with SPF and DKIM, and it can give you reports about who is sending email using your domain.
Start with the IT Club Domain Security Checker →
The short version
Start by finding every legitimate service that sends email using your domain. Make sure each one is authenticated with SPF and/or DKIM, publish DMARC in monitoring mode, review the reports and move gradually towards enforcement.
- p=none means monitor only; it does not stop spoofed email.
- Quarantine asks receiving systems to treat failing messages as suspicious, usually by sending them to spam.
- Reject asks receiving systems not to accept failing messages.
- Do not enforce a policy until you understand your legitimate senders.
What SPF, DKIM and DMARC mean
| Control | Plain-English meaning | Think of it as |
|---|---|---|
| SPF | A DNS record that lists servers and services allowed to send email for your domain. | A guest list for senders. |
| DKIM | A digital signature that helps show a message came from an authorised source and was not altered in transit. | A tamper-evident seal. |
| DMARC | Instructions for receiving mail systems when SPF or DKIM checks fail, plus a way to receive reports. | A set of receiving instructions and an activity report. |
DMARC checks alignment as well as authentication. In simple terms, the authenticated domain needs to relate correctly to the domain visible in the From address. The technical details can be handled by your DNS administrator or IT provider; the business decision is to know what is sending email and what policy you are asking receiving providers to apply.
Why this matters now for UK SMEs
Google and Yahoo have introduced stronger authentication expectations for bulk senders. Microsoft also introduced new requirements for high-volume senders to Outlook.com, Hotmail.com and Live.com addresses in 2025. These rules are aimed at improving the wider email ecosystem, but they matter to smaller businesses too: marketing platforms, customer relationship systems, invoicing tools and other services may send using your domain even when your normal office email is configured correctly.
Correct authentication can make it harder for criminals to impersonate your domain and can improve the chance that legitimate messages are accepted. It is not a guarantee of inbox placement, and it does not make every phishing email disappear. It is one part of a broader email-security and deliverability process.
Check your current position
- 1Ask your IT provider to show your current DMARC, SPF and DKIM records and provide recent DMARC reports.
- 2List every system that may send email using your domain: office email, CRM, marketing, finance, payroll, booking, delivery, website forms and third-party portals.
- 3Use a reputable DNS or DMARC checker to view the published records and identify missing or obviously broken configuration. Treat any automated result as a starting point, not as a complete audit.
- 4Check the DMARC policy. p=none is monitoring only; p=quarantine is a transition towards enforcement; p=reject is the strongest policy.
- 5Record who owns each sending service and who is responsible for fixing authentication failures.
A domain can have a valid-looking DMARC record and still have legitimate services failing authentication. The record itself is not proof that the whole sending environment is healthy.
What good looks like for an SME
- There is a complete, current list of services that send mail using the business domain.
- SPF and DKIM are configured for legitimate sending services, with alignment checked rather than assumed.
- DMARC reports are sent to a monitored destination and reviewed regularly.
- Unknown sources are investigated rather than automatically added to SPF.
- The policy is enforced only after legitimate senders are understood and authenticated.
- There is an owner and review process for new services that send email.
A safe checklist: from p=none to enforcement
- 1Inventory your senders. Include systems that send only occasional invoices, alerts, forms or notifications.
- 2Ask each supplier how it supports SPF, DKIM and domain alignment. Record the supplier contact and the internal technical owner.
- 3Publish or update SPF and DKIM for each legitimate service through the person who manages your DNS. Do not change DNS yourself if you are unfamiliar with the consequences.
- 4Publish DMARC with p=none and reporting enabled. Keep this monitoring stage long enough to see normal sending patterns, including monthly or seasonal services.
- 5Review reports and fix legitimate failures. This may mean enabling DKIM, correcting a sending domain, changing an SPF record or following a supplier's domain-authentication process.
- 6Move to p=quarantine for a transition period. Monitor spam placement and investigate any genuine messages that are affected.
- 7Move to p=reject when reports show that legitimate services pass and the business understands how to respond when a new sender is added. Continue monitoring after enforcement.
Do not treat p=reject as a one-time switch. A new CRM, website platform, payroll service or marketing tool can become a new legitimate sender. Add email authentication to the supplier-onboarding checklist.
What to expect from your IT provider
- A clear inventory of sending services, including those still awaiting verification.
- Evidence of SPF and DKIM configuration, or documentation showing where a third party manages it.
- Recent DMARC reports and a short remediation plan for failures.
- A staged plan from monitor to quarantine to reject.
- Checkpoints, an owner for each action and a rollback or recovery plan if legitimate email is disrupted.
A good provider should be able to explain the difference between a technical requirement, a supplier preference and a service it is recommending. It should also tell you what you will own and how you will know whether the work is complete.
Five questions to ask your IT provider
- 1Which services send email using our domain, and who is responsible for each one?
- 2Are SPF and DKIM configured and aligned for all these services? Please show me the evidence.
- 3What DMARC policy do we currently publish, and can you provide recent reports?
- 4What is the staged plan to move from p=none to p=quarantine or p=reject, and how will you detect and fix legitimate mail that gets blocked?
- 5How will we be informed if a third party starts failing authentication and risks our deliverability?
Read the longer guide: Could Someone Be Sending Fake Emails as Your Business? →
Read: Why Your Business Needs DMARC →
Download: DMARC Business Guide →
What results should you aim for?
The aim is not a perfect dashboard number. You want unauthorised messages pretending to come from your domain to be more likely to be quarantined or rejected, while legitimate services remain authenticated and deliverable.
Those outcomes depend on careful identification and verification. DMARC is not a substitute for sensible payment verification, phishing awareness, email filtering, secure accounts or a tested incident process.
Your next step
Ask your IT provider for your current DMARC, SPF and DKIM position and recent reports. Then work through the sender inventory before changing the policy.
Start with the IT Club domain and email-security checker for a point-in-time view of your public records. Then use this checklist to understand the results and decide what to ask your provider.
Check your domain and email security → →
Sources and further reading
The definitions and staged-policy guidance in this article follow the published DMARC model. The current sender-rule context is based on the mailbox providers' own guidance and announcements. Requirements can change, so check the current provider documentation before treating a threshold or enforcement date as permanent.
Google: Email sender guidelines →
Yahoo: Sender best practices →
Microsoft: Strengthening the email ecosystem for high-volume senders →
Plain-English Takeaway
Start with visibility. Inventory every legitimate sender, authenticate each one, review DMARC reports and only move from p=none to quarantine or reject when you understand what will be affected.
Frequently asked questions
What does DMARC do for a small business?
DMARC tells receiving mail systems how to handle messages that claim to come from your domain but fail authentication checks. It can also send reports showing who is sending mail using your domain. It helps reduce domain spoofing, but it does not replace email filtering, staff training or other security controls.
Is p=none enough for DMARC?
p=none is a monitoring policy. It lets you receive reports about authentication results but does not ask receiving systems to quarantine or reject failing messages. It is a sensible starting point, not the same as enforcement.
Can I move straight from p=none to p=reject?
You can publish any policy, but moving straight to reject is risky if legitimate services have not been identified and authenticated. Review reports, fix SPF and DKIM for every genuine sender, consider a quarantine transition and test for unintended disruption before using reject.
Does DMARC guarantee that emails reach the inbox?
No. DMARC helps receiving systems verify domain authentication and can improve trust, but inbox placement also depends on reputation, content, recipient engagement, sending practices and the receiving provider's own rules.
What should I ask my IT provider about DMARC?
Ask which services send email using your domain, whether SPF and DKIM are aligned for each service, what policy you publish, who reviews reports and how the provider will stage enforcement without blocking legitimate messages.
Related Articles
You Can't Fix Every Cybersecurity Risk at Once. So What Comes First?
There will always be more cybersecurity work than time and budget. Here is a practical way to decide what genuinely needs fixing first.
Read articleCould Your Business Refuse a Ransom Demand?
Stadler Rail refused a multimillion-dollar ransom demand after a contained cyberattack. The real lesson is whether your business has enough resilience to do the same.
Read articleAI Agents Are Starting to Hack Without Waiting for Humans
Attackers are beginning to use AI agents to investigate systems, change tactics and work in parallel. Here is what that means for ordinary businesses.
Read article