Knowledge Centre
Cyber SecurityBusiness Security Guide

Business Guide to DMARC

7 minutes to completeEvergreen guide — kept up to date

DMARC, SPF and DKIM work together to help mail systems verify that email claiming to come from your domain was genuinely sent by you. This guide explains what each standard does, why DMARC should be implemented carefully, and what it cannot protect against.

Email spoofing is when a criminal sends an email that displays your company name and domain in the From field — without your knowledge and without access to your email system. DMARC, SPF and DKIM are the three standards designed to reduce this risk.

DMARC does not encrypt email, stop malware, replace MFA, replace email filtering or replace security awareness training. It is one important layer in a broader email security strategy.

The Three Standards

SPF (Sender Policy Framework) lists the servers authorised to send email for your domain. DKIM (DomainKeys Identified Mail) adds a digital signature so receiving servers can verify the message has not been tampered with. DMARC ties both together, requires alignment with the visible From address, defines a policy for failing messages and enables reporting.

DMARC Policy Options

PolicyWhat it doesWhen to use it
p=noneNo action — reports sent to youStart here. Monitor before enforcing.
p=quarantineFailing messages sent to spam/junkAfter reviewing reports and fixing legitimate senders.
p=rejectFailing messages blocked entirelyOnly after thorough monitoring and testing.

What DMARC Does NOT Do

  • Encrypt email content
  • Stop malware or viruses in attachments
  • Block phishing from other domains or look-alike domains
  • Replace Microsoft Defender or endpoint security
  • Replace email filtering or anti-spam software
  • Replace multi-factor authentication (MFA)
  • Replace security awareness training or backups
  • Prevent compromise of a genuine email account

Start with Monitoring — Not Reject

Many businesses send email from services they are not fully aware of: CRM platforms, marketing tools, invoicing software, website contact forms, printers and cloud services. A reject policy will block any of these that are not correctly configured. Always start with p=none, review reports over several weeks, correct all legitimate senders, then move progressively to quarantine and reject.

Common Mistakes

  • Publishing multiple SPF records — a domain must have exactly one.
  • Exceeding the SPF ten DNS-lookup limit by adding too many services.
  • Forgetting third-party senders — CRM, marketing, invoicing, website forms, printers.
  • Never reviewing DMARC reports.
  • Moving to reject before all legitimate senders are correctly configured.

Questions to Ask Your IT Provider

  1. 1Does our domain have SPF, DKIM and DMARC published?
  2. 2What is our current DMARC policy — none, quarantine or reject?
  3. 3Are DMARC aggregate reports being reviewed regularly?
  4. 4Are all our sending services — CRM, marketing, invoicing — included in our SPF record?
  5. 5Are our email-sending services signing with DKIM?
  6. 6When did we last review our email authentication configuration?

Last reviewed: 31 July 2026. Review this guide whenever new cloud services, marketing platforms or suppliers are adopted.

Plain-English Takeaway

DMARC is one of the best ways to stop criminals impersonating your business by email. It works best when combined with SPF, DKIM, MFA, email filtering, security awareness and regular review.

Downloadable guide

Download the DMARC Business Guide

A printable A4 PDF covering how SPF, DKIM and DMARC work, the three policy options, what DMARC does not protect against, common mistakes and a step-by-step implementation guide.

Download Guide

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.