Short answer
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email standard that lets you tell receiving mail servers what to do with messages that falsely claim to come from your domain. Without DMARC enforcement, anyone can put your domain in the From line of an email, which is how most business email compromise, invoice fraud and executive-impersonation attacks work.
In detail
DMARC works with two other standards:
- SPF lists the mail servers allowed to send for your domain
- DKIM adds a cryptographic signature proving a message was authorised by your domain
- DMARC requires the visible From domain to align with an authenticated SPF or DKIM domain, and tells receivers how to handle mail that fails
A DMARC policy has three settings: p=none only reports failures, p=quarantine sends failing mail to spam, and p=reject blocks it. Only an enforced policy of p=reject actually stops spoofing, yet most domains have no DMARC record or sit at p=none.
FirstNet's managed SendMarc service takes you from monitoring to p=reject safely, authenticating every legitimate sender first so marketing and transactional email keeps flowing.
Source: FirstNet Email Security & Threat Protection service page →
Didn’t answer your question?
