Short answer
Yes. DMARC applies to any domain sending email, including mail sent from Microsoft 365 and Google Workspace. For DMARC to be enforced safely, every legitimate sender must pass SPF or DKIM alignment, including Microsoft 365 itself, marketing platforms and finance or ERP systems that send as your domain.
In detail
FirstNet's managed SendMarc service handles this alignment work before moving your policy to enforcement:
- Publishes a monitoring-only DMARC record and collects reports from receiving mail providers
- Identifies every sending source, often 15 to 40, including marketing tools, ERP, transactional and bespoke applications
- Specifies SPF and DKIM settings for Microsoft 365, Google Workspace and each other platform, which your administrators apply under FirstNet's guidance
- Moves the policy from p=none to p=quarantine to p=reject, with go or no-go reviews and rollback guardrails
DMARC complements, rather than replaces, inbound email security. FirstNet runs Mimecast in front of Microsoft 365 or Google Workspace to filter phishing reaching your users, while SendMarc stops attackers spoofing your domain to others.
Once DMARC is enforced, BIMI can display your logo in Gmail, Apple Mail and Yahoo.
Source: FirstNet Microsoft 365 Security & Compliance service page →
Didn’t answer your question?
