Short answer
It depends on how many sending sources you have and how quickly your platform owners can make authentication changes. FirstNet scopes the journey during discovery rather than committing to a date upfront.
In detail
The steps that drive the timeline:
- Discovery of your primary, secondary and legacy domains, and the business owners of each sending platform
- A baseline DMARC report, which typically lands within two reporting cycles of publishing a monitoring record
- Source classification, which often reveals 15 to 40 sending sources
- SPF and DKIM remediation, platform by platform, with your administrators making changes under FirstNet's guidance
- The move to p=quarantine, then p=reject, with each step gated on a go or no-go review
The remediation stage usually takes longest, because each marketing platform, ERP or bespoke application owner has to make and test changes. Organisations that bring those owners in early move faster, while extra domains found during discovery, or acquisitions, add to the scope.
After p=reject, steady-state operation continues with monthly reviews, authentication of new sources and optional BIMI deployment.
Source: FirstNet Email Security & Threat Protection service page →
Didn’t answer your question?
