GlossarySecurity awareness

DMARC

Short answer

DMARC is an email authentication standard that tells receiving mail servers what to do with messages that claim to come from your domain but fail SPF or DKIM checks: deliver them, send them to spam or reject them. It protects the domain from being spoofed in phishing and fraud.

How SPF, DKIM and DMARC work together

SPF lists the servers allowed to send email for a domain. DKIM adds a cryptographic signature that proves a message was not altered and comes from an authorised sender. DMARC builds on both: it checks that the domain the recipient sees matches the one verified by SPF or DKIM, applies the policy published in the domain's DNS, and sends reports on who is sending email in its name.

The three policies

p=none only monitors and reports. p=quarantine sends failing messages to spam. p=reject blocks them. The usual approach is to start with none, use the reports to find every legitimate sender (marketing tools, CRM, invoicing software), fix their configuration and then move to quarantine and reject. A DMARC record left at none protects nothing.

Why it matters

Without DMARC, anyone can send an email that appears to come from your exact domain, a common starting point for phishing and BEC fraud against customers, suppliers and employees. Since 2024, Google and Yahoo require DMARC from bulk senders. DMARC does not stop lookalike domains, so awareness training is still needed. The DMARC.org site explains the standard and links to its specification.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub