Could Someone Be Sending Fake Emails as Your Business?

DMARC helps prevent criminals pretending to send emails from your business. Learn how it works, why it matters and what your IT provider should monitor.
Imagine a customer receives an invoice that appears to come from your company. It contains your business name. Your domain. Your branding. But you never sent it.
Email spoofing happens every day. DMARC helps reduce the likelihood that criminals can successfully impersonate your domain — and the key message of this article is that DMARC protects your business reputation as much as your inbox.
What is email spoofing?
Criminals can forge the “From” address of an email, so recipients believe it genuinely came from your business, your finance department, your managing director or your support desk.
- Invoice fraud and payment diversion
- Phishing and credential theft
- Malware delivery
- Reputational damage
What is DMARC?
DMARC stands for Domain-based Message Authentication, Reporting and Conformance — but the acronym matters far less than what it does. DMARC tells receiving email systems how to check whether an email is genuine, what to do if it is not, and where to send reports about suspicious activity.
Think of it as a published set of instructions for anyone receiving email from your domain.
How does DMARC work?
DMARC builds on two other checks that work together behind the scenes:
- SPF confirms which mail servers are allowed to send email for your domain.
- DKIM adds a digital signature proving the email has not been altered.
- DMARC checks whether SPF and/or DKIM pass correctly and align with your domain — then tells the receiving email system whether to allow, quarantine or reject the message.
Why should businesses care?
Customers trust your domain. If criminals abuse it, they may steal money, steal passwords, damage trust, reduce email deliverability and cause suppliers to distrust genuine messages. DMARC helps protect your reputation, customers, suppliers, employees and brand identity.
What happens if you don’t use DMARC?
Nothing may appear wrong — until someone starts impersonating your domain. Without DMARC, fake emails may be harder to detect, you receive no useful reporting, legitimate emails may suffer poorer deliverability, and customers have less protection.
What are the different DMARC policies?
| Policy | What it means | Typical use |
|---|---|---|
| None | Monitor only. Collect reports. No enforcement. | The usual starting point |
| Quarantine | Suspicious emails are normally treated as spam. | The middle step |
| Reject | Failing emails are rejected before reaching the inbox. | The strongest protection |
Most organisations begin with monitoring before moving gradually towards reject.
What are DMARC reports?
Receiving email providers send reports showing who is sending email using your domain, whether authentication passed, whether unknown senders exist, and whether spoofing attempts are occurring.
The reports are technical. Most businesses use software or their IT provider to interpret them.
Can DMARC be set and forgotten?
No. Businesses regularly add services such as CRM systems, marketing platforms, payroll software, booking systems, websites and ticketing systems. These may send email legitimately — and if they are not configured correctly, they may fail DMARC.
Monitoring remains important. This is part of the operational heartbeat: as your business changes, your email systems change too, and someone needs to keep the configuration accurate.
Common misconceptions
DMARC does NOT:
- Encrypt email
- Stop every phishing email
- Protect personal Gmail accounts
- Replace antivirus
- Replace staff awareness training
- Eliminate all fraud
DMARC DOES:
- Make domain impersonation harder
- Improve trust
- Improve deliverability
- Provide visibility
- Help protect your brand
What should your IT provider check?
- SPF record exists
- DKIM enabled
- DMARC record published
- Policy reviewed
- Reporting configured
- Unknown senders investigated
- Third-party email systems authorised
- DNS reviewed
- Regular monitoring in place
- Deliverability tested
- Reject policy considered where appropriate
Signs your business should review DMARC
- Customers report strange emails.
- Marketing emails aren’t arriving.
- Suppliers query your messages.
- You changed email providers.
- You added a CRM.
- You use Microsoft 365 or Google Workspace.
- Your website sends forms.
- You use payroll software.
- You have never heard of DMARC.
Why business owners should care
DMARC isn’t simply an IT setting. It protects trust, reputation, payments, customer confidence and business communications. Many attacks succeed because recipients believe the email genuinely came from your business.
The IT Club View
Most businesses lock their office door. They should also lock their email identity. DMARC is one of the simplest ways to reduce domain impersonation — but its value comes from ongoing monitoring, not simply publishing one DNS record.
As your business changes, your email systems change too. Someone should regularly check that every legitimate sender is authenticated and every unknown sender is investigated.
Three questions to ask your IT provider
- 1Do we have DMARC enabled?
- 2What policy are we using?
- 3Who checks the reports?
If you don’t know the answers, it’s worth asking.
Technical note for IT administrators
DMARC evaluates SPF and DKIM alignment: the domain in the visible From header must align with the domain validated by SPF (Return-Path) or signed by DKIM (d= tag). Alignment can be relaxed (default, organisational domain match) or strict (exact match), set via the aspf and adkim tags.
The policy is published as a DNS TXT record at _dmarc.yourdomain. Key tags: p= (policy for the domain), sp= (policy for subdomains), rua= (aggregate report destination), ruf= (forensic/failure reports, where supported), and pct= (percentage of messages the policy applies to during rollout).
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.comDo not copy this directly. Every organisation should create a policy appropriate to its own email services, starting at p=none with aggregate reporting, then tightening once all legitimate senders are authenticated.
Plain-English Takeaway
DMARC helps stop criminals pretending to send email from your business. It works alongside SPF and DKIM to protect your reputation, improve email trust and reduce the risk of domain impersonation—but it still needs monitoring.
Related Articles
Microsoft Is Making Passkeys the Default: Is Your Business Ready?
Microsoft is making passkeys the default Entra authentication experience. Learn what this means for MFA, SMS authentication and business security.
Read articleWhatsApp Usernames Are Coming — Would You Recognise a Fake One?
WhatsApp usernames may improve privacy but could also create new impersonation risks. Learn how businesses can verify contacts and protect customers.
Read articleThe UK Isn’t Banning VPNs — But Is Yours Fit for Business?
The UK has decided not to restrict VPN access. Learn what the decision means and how to check whether your business VPN is properly secured.
Read article