← All terms

DMARC

DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard that tells receiving servers how to handle messages that fail SPF or DKIM checks, blocking exact-domain spoofing.

DMARC — Domain-based Message Authentication, Reporting and Conformance — is a DNS-published policy that closes the oldest hole in email: anyone, by default, can send a message claiming to be from your domain. DMARC lets a domain owner declare that mail failing authentication should be quarantined or rejected, and asks receiving servers to report back on what they saw.

How it works

DMARC builds on two older standards. SPF lists the servers authorized to send mail for a domain; DKIM adds a cryptographic signature proving a message was sent, unaltered, by the domain's infrastructure. DMARC adds the missing enforcement layer: a DNS TXT record stating what receivers should do when a message fails both checks — and, critically, requiring that the domain shown to the human (the From header) aligns with the domain that passed authentication.

The policy escalates in three steps. p=none only monitors: mail flows unchanged while aggregate reports reveal who is sending as your domain. p=quarantine sends failing mail to spam. p=reject refuses it outright — the end state that makes exact-domain spoofing effectively impossible at participating receivers. Major mailbox providers now require DMARC from bulk senders, which has pushed adoption from best practice toward baseline.

What it does not stop

DMARC protects your exact domain — nothing else. Attackers respond by registering lookalike domains that pass DMARC perfectly for a domain that merely resembles yours, by compromising a real supplier mailbox (vendor email compromise arrives fully authenticated), or by using display-name tricks on free webmail. That is why business email compromise remains a multi-billion-dollar category even as DMARC adoption climbs — our BEC defense playbook covers the human and process layers that have to carry the rest.

How to defend

  • Publish DMARC and move to p=reject in stages, using aggregate reports to find legitimate senders (marketing tools, CRMs) before enforcement breaks them.
  • Treat authentication as one layer. Train finance and procurement teams on the attacks DMARC cannot see: lookalike domains, compromised vendor threads, and urgent payment pretexts.
  • Monitor the reports. DMARC reporting shows abuse of your brand in the wild — useful early warning that a phishing campaign is impersonating you toward customers or partners.

Related terms

SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.Business Email Compromise (BEC)Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.Vendor Email Compromise (VEC)Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo