Business Guide to DMARC
DMARC, SPF and DKIM work together to help mail systems verify that email claiming to come from your domain was genuinely sent by you. This guide explains what each standard does, why DMARC should be implemented carefully, and what it cannot protect against.
Email spoofing is when a criminal sends an email that displays your company name and domain in the From field — without your knowledge and without access to your email system. DMARC, SPF and DKIM are the three standards designed to reduce this risk.
DMARC does not encrypt email, stop malware, replace MFA, replace email filtering or replace security awareness training. It is one important layer in a broader email security strategy.
The Three Standards
SPF (Sender Policy Framework) lists the servers authorised to send email for your domain. DKIM (DomainKeys Identified Mail) adds a digital signature so receiving servers can verify the message has not been tampered with. DMARC ties both together, requires alignment with the visible From address, defines a policy for failing messages and enables reporting.
DMARC Policy Options
| Policy | What it does | When to use it |
|---|---|---|
| p=none | No action — reports sent to you | Start here. Monitor before enforcing. |
| p=quarantine | Failing messages sent to spam/junk | After reviewing reports and fixing legitimate senders. |
| p=reject | Failing messages blocked entirely | Only after thorough monitoring and testing. |
What DMARC Does NOT Do
- Encrypt email content
- Stop malware or viruses in attachments
- Block phishing from other domains or look-alike domains
- Replace Microsoft Defender or endpoint security
- Replace email filtering or anti-spam software
- Replace multi-factor authentication (MFA)
- Replace security awareness training or backups
- Prevent compromise of a genuine email account
Start with Monitoring — Not Reject
Many businesses send email from services they are not fully aware of: CRM platforms, marketing tools, invoicing software, website contact forms, printers and cloud services. A reject policy will block any of these that are not correctly configured. Always start with p=none, review reports over several weeks, correct all legitimate senders, then move progressively to quarantine and reject.
Common Mistakes
- Publishing multiple SPF records — a domain must have exactly one.
- Exceeding the SPF ten DNS-lookup limit by adding too many services.
- Forgetting third-party senders — CRM, marketing, invoicing, website forms, printers.
- Never reviewing DMARC reports.
- Moving to reject before all legitimate senders are correctly configured.
Questions to Ask Your IT Provider
- 1Does our domain have SPF, DKIM and DMARC published?
- 2What is our current DMARC policy — none, quarantine or reject?
- 3Are DMARC aggregate reports being reviewed regularly?
- 4Are all our sending services — CRM, marketing, invoicing — included in our SPF record?
- 5Are our email-sending services signing with DKIM?
- 6When did we last review our email authentication configuration?
Last reviewed: 31 July 2026. Review this guide whenever new cloud services, marketing platforms or suppliers are adopted.
Plain-English Takeaway
DMARC is one of the best ways to stop criminals impersonating your business by email. It works best when combined with SPF, DKIM, MFA, email filtering, security awareness and regular review.
Downloadable guide
Download the DMARC Business Guide
A printable A4 PDF covering how SPF, DKIM and DMARC work, the three policy options, what DMARC does not protect against, common mistakes and a step-by-step implementation guide.
Download GuideFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Operational Heartbeat Checklist
A plain-English checklist for business owners to assess whether their IT provider is monitoring the right things. Covers backups, servers, Microsoft 365, firewalls, security, certificates, storage and more.
View guideBusiness Backup Checklist
Confirm what is backed up, where it goes and who checks that it works.
Coming SoonCyber Resilience Readiness Guide
Review your critical systems, IT suppliers, incident response, backups and business-continuity arrangements.
View guide