Short answer
A baseline DMARC report shows every system sending email as your domain. FirstNet publishes a monitoring-only DMARC record (or uses your existing one) and collects the reports that receiving mail providers send back, usually over two reporting cycles.
In detail
How the discovery works:
- Aggregate (RUA) reports from receiving mail providers list pass and fail results for each sending source
- Forensic (RUF) reports, where providers send them, give samples of failed messages and reveal specific impersonation attempts
- The SendMarc platform turns these reports into one inventory of sending IP addresses, platforms and alignment status
- Each source is classified as legitimate, a forwarder or unauthorised, and shared with your business owners
Most organisations discover far more senders than expected, often 15 to 40 sources including marketing platforms, ERP and finance systems, and some they do not recognise. Legacy domains and domains from acquisitions often still send mail too.
A monitoring-only record does not block or change any mail, so discovery carries no delivery risk. The inventory then becomes the plan for authenticating legitimate senders before FirstNet moves your policy towards enforcement.
Source: FirstNet Email Security & Threat Protection service page →
Didn’t answer your question?
