Here’s what surprises people: having a DMARC record isn’t the same as being protected by one.
DMARC has three policy settings. p=none watches and reports but blocks nothing. p=quarantine sends failed messages to spam. p=reject stops them cold. The overwhelming majority of domains that publish a DMARC record never move past p=none — which means they’re collecting data on the attacks while doing nothing to stop them.
If your analyzer result came back with a record in place but a low score, that gap is almost certainly why.
Getting to enforcement is where it gets delicate. Flip to p=reject without a complete inventory of every platform that sends mail on your behalf — your CRM, your billing system, your marketing tool, your ticketing platform — and you don’t just block attackers. You block your own invoices. That’s the work: finding every sender, authorizing the legitimate ones, and stepping the policy up without breaking anything.
| Record | What It Does | What Happens Without It |
|---|---|---|
| SPF Sender Policy Framework |
Publishes the list of servers authorized to send as your domain. | Any server anywhere can send as you. Also breaks silently past ten DNS lookups — a limit most inherited records exceed. |
| DKIM DomainKeys Identified Mail |
Cryptographically signs each message so recipients can verify it wasn't altered. | No proof a message is genuinely yours or arrived unmodified. SPF alone can't establish this. |
| DMARC Domain-based Message Auth., Reporting & Conformance |
Tells receiving servers what to do when SPF or DKIM fails, and reports who's sending as you. | No enforcement and no visibility. Spoofed mail is delivered normally and you never see it. |
Sender Policy Framework
What It Does
Publishes the list of servers authorized to send as your domain.
What Happens Without It
Any server anywhere can send as you. Also breaks silently past ten DNS lookups — a limit most inherited records exceed.
DomainKeys Identified Mail
What It Does
Cryptographically signs each message so recipients can verify it wasn’t altered.
What Happens Without It
No proof a message is genuinely yours or arrived unmodified. SPF alone can’t establish this.
Domain-based Message Auth., Reporting & Conformance
What It Does
Tells receiving servers what to do when SPF or DKIM fails, and reports who’s sending as you.
What Happens Without It
No enforcement and no visibility. Spoofed mail is delivered normally and you never see it.
All three have to be in place and aligned with one another. Two out of three leaves the door open.
Google and Yahoo now enforce authentication requirements on bulk senders, and other providers keep tightening. Domains without proper records see messages delayed, filtered to spam, or rejected outright. If your campaigns or invoices are underperforming, this is a common cause.
Cyber insurance applications increasingly include email authentication questions. CMMC, PCI DSS, and HIPAA-aligned security programs expect controls that prevent impersonation of your organization. We provide the documentation.
Healthcare · Financial Services · Not-for-Profit · Property Management — sectors where one spoofed message can trigger a fraudulent payment, expose protected information, or cost a donor relationship built over years.
Full DNS and authentication audit. We inventory every service sending mail on your behalf, analyze your SPF record for syntax and lookup-limit problems, and deliver a prioritized gap report.
SPF rebuilt and optimized. DKIM keys generated and published across every sending platform. DMARC deployed in monitoring mode so we can see the full picture before anything gets blocked.
We read the DMARC reports, identify unauthorized senders and spoofing attempts, authorize the legitimate services we find, and advance your policy from monitor to quarantine to reject in controlled steps.
Continuous monitoring with alerting on authentication failures. Monthly reporting on domain reputation and enforcement status. DKIM key rotation. Change management as you add new platforms.
What we need from you: DNS access (or your registrar contact), and about an hour of someone’s time to confirm the sending platforms we discover. That’s it.
The DNS records themselves aren’t complicated. The hard part is discovering every legitimate sender before you enforce, and interpreting DMARC reports afterward — they arrive as raw XML from dozens of receiving servers. Most self-managed deployments stall at p=none for exactly this reason.
Not if it’s sequenced correctly. That’s why we run monitoring mode first: we identify and authorize every legitimate sender before any policy starts blocking. Skipping that step is how organizations end up blocking their own invoices.
Records go live in the first couple of weeks. Full enforcement typically lands at 60 to 90 days, because the monitoring period needs enough traffic to surface every sender — including the quarterly billing run or annual mailing nobody remembered.
Microsoft 365 provides a default SPF include and can sign with DKIM, but it doesn’t inventory your third-party senders, doesn’t publish or manage your DMARC policy, and doesn’t advance you to enforcement. Those remain your responsibility.
It queries your domain’s public DNS for SPF, DKIM, and DMARC records, validates syntax and alignment, and flags gaps. It reads nothing else — no mailboxes, no message content, no internal systems.
ION247 is a managed security service provider delivering IT services, consulting, and cybersecurity in Orlando and nationwide. Email authentication sits alongside advanced threat protection, security awareness training, and 24/7 managed detection and response within our DEFCON cybersecurity programs.