What is DMARC?

What is DMARC?


Everything you need to know about DMARC!

DMARC (Domain-based Message Authentication Reporting and Conformance) is an email validation system which can defend your organisation and customers against advanced email threats like phishing attacks and spam emails.
DMARC protects an organisation and its individuals from spam emails thereby protecting the company from frauds. It allows an organisation to set up certain policies and rules that define the authentication of the emails sent in its name. Besides this, with DMARC, you can control what happens to the emails that fail to follow the policies and send to spam or even delete them.

DMARC combines the widely used SPF and DKIM protocols to ensure that an email’s “From: ” field is authentic and if not, via DMARC it can be reported to the concerned bodies.


History of DMARC

Founded in 2012, DMARC standard was published to prevent email abuse that was not being taken care by SPF (Sender Policy Framework) and DKIM (Domain Keys Identified Mail) standards that had been in practice since 15 years. It was created by industry leaders like PayPal, Google, Microsoft and Yahoo.
DMARC works on the basis of SPF and DKIM and is originally developed as an email security protocol at the DNS level. Current DMARC adoption rate globally is low but its importance has led almost all governing authorities to make its implementation compulsory for member organisations. DMARC serves as a tool to prevent spoofing and increase email deliverability to gain the maximum ROI from an organisation’s most critical asset: Email.

How Does DMARC Help?


Phishing attacks have risen by 350% during the COVID-19 Pandemic!

$600 million every year is scammed by Phishing attacks!

Globally 1 in 3 companies have been victims of CEO Fraud Email Scams!

DMARC has been adopted by the biggest email senders and email receivers globally. This includes Yahoo!, Google, and Microsoft, covering 85% of the consumer inboxes in the world.
The most important reason why DMARC should be used is that it gives an organisation full control on how their domain is being used. The organisation can also instruct the receivers on what actions should be taken if the incoming email is not legitimate and report the incident back to the organisation for further analysis.
It saves consumers from the trouble of identifying whether an email is legitimate or a spam. Sometimes it may happen that regardless of all the knowledge of email spoofing a receiver might fall into the trap. DMARC makes sure that this does not happen.

DMARC Architecture

Image Credit: Global Cyber Alliance

There have been other protocols and frameworks that focus on security of an email while in transit (S/MIME Encryption, SSL/TLS Handshakes & Digital Certificates etc.), but these, along with originally used SPF and DKIM protocols on the DNS, were not enough to stop someone from phishing with your domain!

What kind of reports are sent back if you implement DMARC?

Aggregate Reports

Forensic Reports


Common misconceptions about DMARC!

DMARC’s “p=reject” policy enforces the recipient server to reject the email delivery to inbox of the recipients if it is failing DMARC. Implementing this without proper intelligence and whitelisting can result in your emails not getting delivered and eventually not obtaining any result out of your campaigns. Get in touch with our team immediately if you’re currently facing any difficulty in your email deliverability!

DMARC only governs the outbound channel of your email, i.e. it only concerns with legitimate senders of the email that can use your domain. Having a DMARC on your domain does not tackle incoming phishing attacks, it only stops hackers using your domain to send emails anywhere.

Yes, ability of your domain to be spoofed is not tackled by your domain just having a DMARC record. It depends on the policy of enforcement your DMARC is on. Organisations often put a DMARC record just to comply with certain authorities or governments, however, this does not make your domain safe from hackers.

Eliminate Phishing Attacks and Increase Email Deliverability!