Somewhere in your DNS settings there is probably a record that starts with “v=DMARC1” and continues with “p=none.” Somebody added it during an audit or an insurance questionnaire. It has been sitting there ever since, doing exactly what it was told to do, which is nothing.

That record is not a mistake. It is the correct first step and everyone starts there. The problem is that most businesses never take the second step, and monitoring mode does not stop anyone from sending email that appears to come from your domain. It only tells you it happened. Meanwhile the major mailbox providers have raised what they expect from senders, so finishing buys you protection against impersonation and better deliverability at once.

Why Most Businesses Stop at Monitoring

The honest reason is fear, and it is not irrational. Enforcement means telling the world’s mail servers to reject messages that claim to be from your domain but cannot prove it. Miss one service that legitimately sends for you and its mail starts disappearing. Nobody wants to be the person who broke the invoice emails.

The reports do not help. They arrive as compressed attachments full of XML, a format built for computers rather than humans, so most people file them away with a mail rule. And nothing bad appears to be happening, because monitoring mode is silent by design.

The organizations that write the standards call this a halfway point. M3AAWG, the industry working group whose members include most large mailbox providers, published email authentication best practices in 2020 describing a policy of none and a percentage tag below full coverage as “transitional states, with the goal of removing them as quickly as possible.” Transitional. Not a destination.

What DMARC Actually Does, in Plain English

Think of your domain name as your company letterhead. Anybody can print it. Email was designed in an era of mutual trust, so nothing stops a stranger from putting your company name in the From line.

Three technologies fix this in layers. SPF is a published list of who is authorized to send using your name, like a guest list at the door. DKIM is a tamper-evident seal on each message that a receiver can verify mathematically. As dmarc.org explains, DMARC “builds upon both the DomainKeys Identified Mail (DKIM) and Sender Policy Framework (SPF) specifications,” adding what those were missing: a way to tell receiving servers what to do when a message fails, and a way for them to report back.

You get three choices. None means take no action and just send reports. Quarantine asks receivers to treat failing mail as suspicious, which usually means the junk folder. Reject asks them, in the words of dmarc.org, to “outright reject all non-aligned messages.” Only the last two stop an impersonation attempt from reaching your customer’s inbox, which is why this matters for the targeted fraud we covered in our piece on the surge in phishing attacks and why blocking them remains a challenge.

Reading the Reports Without Becoming an Expert

You do not need to read raw XML. Use a report processing service. Several are free at small business volumes and turn the attachments into a readable dashboard. M3AAWG’s 2020 guidance recommends every record include a tag pointing to a mailbox that receives aggregate reports, because “without the ability to receive and process reports, the domain owner cannot know whether or not it is safe to move from p=none to stricter policies.”

Once you have a dashboard, you are sorting what you see into three piles.

  • Sources you recognize that are passing. Your mail platform, your marketing tool, your accounting system. Done. Leave them alone.
  • Sources you recognize that are failing. Your work list. Usually a service that was never configured to sign your mail properly, and the fix is a vendor support article plus a DNS record or two.
  • Sources you do not recognize. Some will be forwarding, which is normal. Some will be a tool a department signed up for without telling anyone. And some will be people impersonating you, which is why you started this.

Find Every Service That Sends Mail as You

This step decides whether the project succeeds, and it is more tedious than technical. Reports only show what sent during the observation window, so quarterly and annual senders do not appear until they do, and then they fail. Build the list deliberately.

  • Your primary mail platform. Usually the easiest to verify.
  • Marketing and newsletter platforms. Including any a department set up on its own. Ask, do not assume.
  • Billing, invoicing, and payment systems. These matter most, because a customer who stops receiving invoices stops paying on time.
  • Ticketing, scheduling, CRM, and e-signature tools. Anything that emails a customer on your behalf.
  • Payroll, benefits, and applicant tracking systems. Missed constantly, because HR owns them and nobody thinks of HR as a sender.
  • The office equipment. The copier that scans to email, the alarm system, the backup software that mails a nightly report. Classic forgotten senders, often configured with your domain in the From line.

Walk this list with each department head. Half an hour of conversation prevents the one broken mail stream that stalls the whole project.

The Staged Path to Enforcement

Nobody flips this switch in one move, and the standards bodies do not expect you to. As dmarc.org puts it, “it is nearly impossible for an organization to flip a switch to production.” Work in stages, and let the reports tell you when each stage is done.

  1. Monitor and collect. Publish a monitoring policy with reporting on and let it run for several weeks, longer if your mail is seasonal. You are building the inventory.
  2. Fix every legitimate sender. Work the list until each known source authenticates correctly. This is the bulk of the effort and there is no shortcut.
  3. Move to quarantine on a small percentage. The standard lets you apply your policy to a fraction of failing mail. Start small and watch the reports.
  4. Raise the percentage to full coverage. Step it up, watching for surprises. Anything that breaks here is something you missed, and you find out with a junk folder rather than a bounce.
  5. Move to reject. The finish line. M3AAWG’s 2020 guidance is direct about the target: “Policy statements should be ‘p=reject’ where possible, ‘p=quarantine’ otherwise.”

Expect a couple of months of light attention, not a weekend. The waiting between stages is doing real work.

The deliverability argument has strengthened too. Google’s published email sender guidelines, which we reviewed in 2026, define a bulk sender as one sending more than 5,000 messages per day to Gmail accounts, and require those senders to set up SPF, DKIM, and DMARC, keep spam rates reported in Postmaster Tools below 0.30%, and support one click unsubscribe on marketing messages. They also require the From header domain to align with either the SPF or DKIM domain. Note that Google allows the DMARC policy itself to be none for that baseline, which is exactly why so many businesses stopped at monitoring and called themselves compliant. Meeting the minimum bar is not the same as protecting your domain.

The Bottom Line

A DMARC record in monitoring mode is a smoke detector with the battery left out. Not useless, because the reports are valuable, but it does not do the job people assume it does. Anyone can still send email wearing your company’s name.

Finishing is not glamorous or fast, but it is finite. Collect for a few weeks, fix your senders, then move through quarantine to reject in measured steps. When you are done, your domain cannot be casually impersonated and your legitimate mail lands more reliably. That sits squarely within why cybersecurity is no longer optional for mid-sized businesses.

If you have a monitoring record gathering dust and no appetite for reading XML, we run this project for small and mid-sized businesses across Denton County. We will inventory your senders, fix the failing ones, and walk your domain to enforcement without breaking your invoices. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).