Why your business needs DMARC

Why your business needs DMARC

Customers, suppliers and staff often treat the domain in an email’s From address as a sign of identity. Without aligned authentication and a published DMARC policy, the domain owner has less visibility into how participating receivers evaluate messages using that exact domain.

DMARC creates a controlled way to observe that use, correct legitimate senders and ask receiving systems how to handle failures. It helps reduce exact-domain spoofing risk; it does not stop every form of phishing or fraud.

Check your domain · How DMARC works

Four reasons to evaluate DMARC

See the sending surface

Aggregate reports can reveal services observed using the domain and show whether SPF or DKIM aligns.

Create clear ownership

A sender inventory connects mail systems, DNS changes and business owners instead of treating authentication as an isolated record.

Correct legitimate mail deliberately

Evidence helps teams fix return-path or signing configuration before requesting stronger receiver handling.

Maintain a receiver-facing policy

The domain owner can publish a monitoring or enforcement request and continue reviewing change over time.

Your domain sends email from more places than you realise

A business domain is rarely used only by staff mailboxes. Websites, CRM platforms, newsletters, billing systems and support tools may all send mail using the same From domain. DMARC aggregate reports help bring those sources into one view so legitimate services can be verified, authentication gaps corrected and unfamiliar activity investigated before enforcement.

Business systems sending email through one domainStaff email, websites, CRM, newsletters, billing systems and support platforms can all send using one business domain. Vigil uses DMARC evidence to separate aligned sources, sources needing authentication work and unexpected sources requiring investigation.Staff emailMicrosoft 365 / GoogleWebsite & formsWordPress / web hostingCRM & salesLeads / notificationsNewslettersCampaign platformsBilling systemsInvoices / statementsSupport platformsTickets / service alertsYOUR DOMAINFrom domain:yourdomain.co.zaVigil builds the sending inventoryEvidence across every sourceExpected & alignedNo action needed!Known; fix neededAuthentication gap?Unexpected sourceInvestigate beforeenforcingBusiness systems sending email through one domainStaff email, websites, CRM, newsletters, billing systems and support platforms can all send using one business domain. Vigil uses DMARC evidence to separate aligned sources, sources needing authentication work and unexpected sources requiring investigation.YOUR DOMAINFrom domain:company.co.zaStaff emailM365 / GoogleWebsite & formsForms / hostingCRM & salesLeads / noticesNewslettersCampaign toolsBilling systemsInvoices / billingSupport toolsTickets / alertsVigil builds the sending inventoryEvidence across every sourceExpected & alignedNo action needed!Known; fix neededAuthentication gap?Unexpected sourceInvestigate before enforcing
DMARC evidence helps build an inventory of the systems observed using a domain; source identity and business ownership still need to be verified.

What the control covers

DMARC evaluates whether SPF or DKIM passes and aligns with the visible From domain. It supports a requested handling policy and reporting. A receiving system can still apply local policy, and authentication success does not prove that a message is safe or wanted.

How DMARC evaluates aligned mail and an exact-domain spoofA known sending service passes DMARC when SPF or DKIM passes and aligns with the visible From domain. An exact-domain spoof with no aligned result fails and is handled according to the published policy and the receiving provider’s local decision.DMARC passes when either authentication path alignsSPF passes + aligns with From OR DKIM passes + aligns with FromAUTHORISED MAILEXACT-DOMAIN SPOOFKnown sending serviceApproved to use your domainImpersonating senderCopies your From addressAt least one aligned resultSPF aligned ✓or DKIM aligned ✓No aligned resultSPF not aligned ×and DKIM not aligned ×DMARC PASS ✓DMARC FAIL ×Accepted as authenticatedNormal filtering continuesPublished DMARC policy appliesMonitor · quarantine · rejectReceiver retains local discretionHow DMARC evaluates aligned mail and an exact-domain spoofA known sending service passes DMARC when SPF or DKIM passes and aligns with the visible From domain. An exact-domain spoof with no aligned result fails and is handled according to the published policy and the receiving provider’s local decision.DMARC needs one aligned pathSPF passes + aligns with FromORDKIM passes + aligns with FromAUTHORISED MAILKnown sending serviceApproved to use your domainAt least one aligned resultSPF aligned ✓or DKIM aligned ✓DMARC PASS ✓Accepted as authenticatedNormal filtering continuesEXACT-DOMAIN SPOOFImpersonating senderCopies your From addressNo aligned resultSPF not aligned ×and DKIM not aligned ×DMARC FAIL ×Published DMARC policy appliesMonitor · quarantine · rejectThe receiver may also applyits own local policy
A known sending service passes DMARC when at least one authentication path passes and aligns with the visible From domain. A basic exact-domain spoof without an aligned result fails and is then subject to the published policy and the receiver’s own decision.

What it does not replace

DMARC does not protect a compromised mailbox, inspect links or attachments, encrypt content, stop lookalike domains or guarantee delivery. Mailbox access, inbound filtering, staff processes, data protection and incident response require separate controls.

A safe adoption path

  • Confirm who owns the domain, DNS and mail decisions.
  • Inventory business mail and third-party senders.
  • Validate SPF and DKIM for each legitimate path.
  • Publish a valid monitoring policy with an approved report destination.
  • Review evidence across normal and periodic sending.
  • Progress policy only when unresolved legitimate sources and delivery risks are understood.
  • Continue monitoring after every change.
Vigil’s evidence-led progression from monitoring to DMARC enforcementVigil assesses the current setup, observes report data, remediates legitimate sending paths and progresses policy only after the sending baseline is understood, valid senders are aligned and material failures are explained.1ASSESSReview DNSCheck SPF / DKIMSet baselineCurrent posture2OBSERVEAnalyse reportsIdentify sendersExplain anomaliesp=none3REMEDIATEAlign SPF / DKIMCorrect valid mailResolve uncertaintyGaps closed4PROGRESSAdvance policyReview evidenceMaintain controlp=quarantine→ p=rejectEVIDENCE GATES BEFORE POLICY ADVANCES✓ Baseline understoodSending estate is visible✓ Valid senders alignedLegitimate mail verified✓ Failures explainedResidual risk understoodPolicy changes follow evidence — not a fixed timetableVigil’s evidence-led progression from monitoring to DMARC enforcementVigil assesses the current setup, observes report data, remediates legitimate sending paths and progresses policy only after the sending baseline is understood, valid senders are aligned and material failures are explained.1ASSESSRead DNS and auth setupSet the sending baselineCurrent posture✓ Baseline understoodSending estate is visible2OBSERVEAnalyse DMARC dataVerify valid sendersp=none✓ Valid senders alignedLegitimate mail verified3REMEDIATEAlign SPF / DKIMCorrect valid mailGaps closed✓ Failures explainedResidual risk is understood4PROGRESSAdvance policyReview evidencep=quarantine→ p=rejectPolicy changes follow evidence— not a fixed timetableEach advance is reviewed
Vigil advances policy when the sending baseline is understood, legitimate sources are aligned and remaining failures are explained—not according to a fixed timetable.

Read the policy progression guide

Who should own the work

The organisation remains responsible for authorising its domains and senders. Internal IT, an MSP or a specialist provider may coordinate DNS, reporting and remediation when responsibilities and approvals are clear.

Vigil supports assessment, aggregate-report processing, source identification, authentication review, monitoring and evidence-based policy progression. Exact delivery and commercial scope are agreed separately.

FAQ

Is DMARC only for large organisations?

No. The relevant question is whether a domain is used for business email and who can manage its authentication. The operating effort depends on the number and complexity of legitimate senders.

Will publishing DMARC interrupt email?

A valid monitoring policy expresses no requested handling for failures. Stronger policies can affect unauthenticated legitimate mail, which is why evidence and staged change matter.

Does an inbound email filter replace DMARC?

No. Inbound filtering protects a receiving environment; DMARC publishes authentication and policy information for other participating receivers evaluating use of your domain.

Does DMARC stop all impersonation?

No. It addresses unauthorised use of the exact visible From domain, not lookalike domains, display-name abuse or compromised accounts.

Can a provider manage it?

Yes, when the provider is authorised and the responsibilities for DNS, mail-platform changes, report review and policy decisions are explicit.

Start with public evidence

Check what the domain publishes now, then map the result to the systems authorised to send.

Check a domain · Contact Vigil