top of page

Don’t Overlook DMARC: What It Is and Why It Matters

Writer: Kyle Cira
Kyle Cira
Aug 31
4 min read

Updated: Sep 2

"Penguins. Why did it have to be penguins?"
"Penguins. Why did it have to be penguins?"

Imagine your business has a security guard stationed at the front door.


The CEO walks up. The security guard recognizes him, verifies his badge, and lets him inside. Simple enough.


Now imagine three penguins walk up wearing a trench coat and pretending to be the CEO.


The security guard takes one look and knows something isn't right. They don't look like the CEO. Their credentials don't check out.


But there's a problem: The security guard has been instructed to observe suspicious visitors—but not stop them. So, the three penguins walk right through the door.


It sounds ridiculous, but something remarkably similar may be happening with your company's email domain.


Meet Your Email Security Guard: DMARC


DMARC stands for Domain-based Message Authentication, Reporting and Conformance.


Its purpose is to help protect your domain from being impersonated in email.


When an email claims to come from your organization, DMARC works with two important email authentication technologies—SPF and DKIM—to help the receiving email system determine whether that message is legitimate.


Think of them as the security guard's methods for verifying someone's identity.


SPF: "Did You Come From Where You Were Supposed To?"


Sender Policy Framework (SPF) identifies which email infrastructure is authorized to send email on behalf of your domain.


If your organization uses Microsoft 365 for email, for example, your SPF record will generally authorize Microsoft's email infrastructure.


But Microsoft might not be your only legitimate sender.


Your organization could also use:

  • Marketing platforms

  • Customer relationship management systems

  • Payroll or HR platforms

  • Ticketing systems

  • Other third-party services that send email using your domain


Those legitimate senders need to be accounted for when building your email authentication strategy.


Think of SPF as the security guard asking: "Did this person arrive from somewhere we recognize and trust?"


DKIM: "Does Your Badge Check Out?"


DomainKeys Identified Mail (DKIM) provides another method of authentication.


DKIM uses cryptography to digitally sign email. The receiving mail system can validate that signature using a public key published by your domain.


In our security guard analogy, this is like examining the CEO's badge and determining whether it's authentic.


Together, SPF and DKIM provide signals DMARC can use to determine whether email claiming to represent your domain properly authenticates and aligns with the domain the recipient sees.


What Happens When DMARC Detects an Impostor?


This is where your DMARC policy becomes extremely important.


A domain can publish one of three primary DMARC policies:


p=none — Monitor DMARC failures without requesting enforcement.


p=quarantine — Request that messages failing DMARC be treated as suspicious, commonly resulting in placement in spam or quarantine.


p=reject — Request that messages failing DMARC be rejected.


Going back to our penguins.


With p=none, the security guard can recognize that something is wrong and report what happened—but isn't instructed to keep the impostors out.


With p=quarantine, the suspicious visitors get pulled aside.


With p=reject, they're denied entry.


Detection Without Enforcement Isn't the End Goal


A DMARC record configured with p=none can provide valuable visibility.


But it doesn't request enforcement against messages that fail DMARC.


That means an organization can have DMARC deployed and still not be taking full advantage of its ability to protect the domain against email impersonation.


This is why simply asking: "Do we have DMARC?" isn't enough. The better question is: "Is our DMARC configuration actually enforcing a policy?"


P=none Has Its Place, For a Time


There's an important caveat.


A p=none policy has a legitimate purpose.


DMARC should be deployed thoughtfully because organizations frequently have more legitimate email senders than they initially realize.


Imagine moving directly to p=reject before discovering that your marketing department uses a third-party platform to send email using your company's domain.


You could end up rejecting legitimate business email.


That's why p=none is commonly useful during the monitoring and discovery phase of a DMARC implementation.


Organizations can use DMARC reporting to understand which systems are sending mail using their domains, identify legitimate senders, and correct SPF and DKIM configurations where necessary.


Once legitimate mail flows have been identified and properly authenticated, the organization can progress toward enforcement with p=quarantine and ultimately p=reject, where appropriate.


p=none should generally be a step in the journey—not the destination.


Don't Let Three Penguins Impersonate Your CEO


DMARC isn't the most glamorous cybersecurity control.


But properly configured email authentication can make it significantly more difficult for attackers to impersonate your domain and use your organization's identity against employees, customers, vendors, and partners.


And that's why DMARC shouldn't be overlooked.


Your security guard needs to do more than recognize the three penguins in the trench coat.


Eventually, you need to give the guard permission to keep them out.


DMARC Is Only One Piece of Microsoft 365 Security


As important as properly configuring DMARC is, it's only one component of a secure Microsoft 365 environment.


Redeemer Cyber assesses and remediates approximately 180 security controls as part of our Microsoft 365 security services, including critical areas such as:

  • MFA

  • Conditional Access

  • Privileged access

  • Exchange Online

  • SharePoint and OneDrive

  • External sharing

  • SPF/DKIM/DMARC


If you're unsure whether a comprehensive Microsoft 365 Security Assessment is right for your organization, start with our “5 Essential Security Measures for Microsoft 365 You Shouldn't Ignore” blog in the related posts section.


It's a quick way to evaluate several foundational protections that every Microsoft 365 organization should be thinking about.


And if those fundamentals aren't where they should be, Redeemer Cyber can help you assess the rest of your environment and remediate the gaps.


Contact Redeemer Cyber today to strengthen your Microsoft 365 security posture.

 
 
 

Comments


bottom of page