Domain-based Message Authentication, Reporting, and Conformance—policy layer for email authentication.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) builds on SPF and DKIM, adding a policy layer that tells receiving servers how to handle authentication failures and provides reporting. DMARC policies specify whether to quarantine, reject, or accept email failing authentication. DMARC reports show who's sending email using your domain—legitimate services and attackers alike. Full DMARC implementation with enforcement (reject policy) provides the strongest protection against domain spoofing.
Why It Matters
The DSC Perspective:
DMARC is the most effective defence against email spoofing of your domain. Implement DMARC with monitoring first, then progress to enforcement. DMARC reports reveal unauthorised use of your domain.
