
DMARC: Why it is now essential for your business.

Email remains one of the most powerful tools for business communication—but it’s also one of the most exploited. Cybercriminals frequently impersonate trusted brands to launch phishing attacks, steal data, and damage reputations. That’s why DMARC—Domain-based Message Authentication, Reporting and Conformance—has become a critical line of defence.
And now, with Google and Yahoo enforcing mandatory DMARC compliance as well as amendments to UK PCI DSS - it is a requirement for most businesses.
What is DMARC?
DMARC is an email authentication protocol that helps protect your domain from unauthorised use, such as spoofing or phishing. It builds on two existing technologies—SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail)—to verify that an email claiming to come from your domain is actually authorised by you.
In simple terms, DMARC tells receiving mail servers:
- Whether an email is legitimate
- What to do if it isn’t (e.g. quarantine or reject it)
- How to report back to the sender about suspicious activity
Why DMARC matters more than ever
For midmarket businesses, the risks of email-based attacks are significant. A single spoofed email can lead to:
- Data breaches
- Financial fraud
- Loss of customer trust
- Damage to brand reputation
Implementing DMARC helps prevent these threats by ensuring only authorised senders can use your domain. It also improves email deliverability, meaning your legitimate messages are more likely to reach inboxes rather than spam folders.
New regulations make DMARC critical
As of February 2024, Google and Yahoo began enforcing stricter email authentication standards for bulk senders—defined as anyone sending 5,000 or more emails per day. These changes require:
- SPF and DKIM alignment
- A valid DMARC policy published in DNS
- Easy unsubscribe options for recipients
By April 2024, non-compliant senders risk having their emails blocked or marked as spam, significantly impacting marketing, sales, and customer service communications.
This shift is part of a broader industry effort to reduce spam, phishing, and email fraud. For midmarket firms, it means that DMARC is no longer optional—it’s essential for maintaining email credibility and deliverability.
New regulations effective March 2025 mandate businesses handling card payments to enhance email security with DMARC to combat phishing. The PCI DSS v4.0 framework now includes DMARC as a requirement. Organisations that handle payment card data must implement DMARC as part of their compliance obligations.
This means that for any business processing card payments or sending bulk email, DMARC is now mandatory—not just for security, but for regulatory compliance.
What DMARC protects you from
Implementing DMARC helps safeguard your business from:
- Email spoofing: Prevents attackers from sending emails that appear to come from your domain.
- Phishing attacks: Reduces the likelihood of customers or employees falling for fraudulent emails.
- Brand impersonation: Protects your reputation by ensuring only authorised messages are sent under your name.
- Deliverability issues: Ensures your emails reach inboxes, not spam folders.
How to get started with DMARC
- Assess your current email setup: Check if SPF and DKIM are properly configured.
- Publish a DMARC record: Start with a “monitor” policy (
p=none
) to gather data. - Review reports: Use DMARC reports to identify unauthorised senders.
- Enforce your policy: Gradually move to
p=quarantine
orp=reject
to block malicious emails. - Stay compliant: Regularly review your configuration, especially if you use third-party email services.
- Reach out to your MSP: Your MSP will have a solution for DMARC and will be able to implement it for you.
Subscribe here!
Recent Posts
Posts by tag
- technology (124)
- Security (98)
- cyber security (86)
- IT Security (83)
- Cloud (65)
- Microsoft 365 (64)
- modern technology (63)
- Managed Service (62)
- business (60)
- cloud computing (59)
- IT support (58)
- cyber attack (54)
- workplace (54)
- Microsoft Teams (53)
- cloud it (53)
- microsoft (52)
- Working from home (50)
- productivity (48)
- office (46)
- cybersecurity (44)
- office 365 (44)
- IT (41)
- entrustit (39)
- Uncategorised (38)
- employees (38)
- flexible work (36)
- Password Security (35)
- Remote (33)
- efficiency (31)
- Hosted Workspace (30)
- hosted desktop (30)
- schools (29)
- independent schools (28)
- school ict (27)
- collaboration (26)
- 2023 (25)
- Cyber (25)
- it support bournemouth (23)
- cyber privacy (22)
- public cloud (22)
- computing (21)
- email security (21)
- it support dorset (20)
- password (20)
- entrust (19)
- passwords (19)
- hosted applications (18)
- VoIP (17)
- cloud voip (17)
- covid19 (17)
- hacking (17)
- it support hampshire (17)
- private cloud (17)
- data (16)
- teamwork (16)
- Coronavirus (15)
- GDPR (14)
- hackers (14)
- office 365 support (14)
- ransomware (14)
- IT audit (13)
- Protection (13)
- cloud cctv (13)
- covid-19 (13)
- hack (13)
- it consultancy (13)
- it consultancy bournemouth (13)
- it support southampton (13)
- management (13)
- network (13)
- Hosted Desktop and Applications (12)
- Windows Virtual Desktop (12)
- cctv (12)
- hardware (12)
- internet (12)
- it consultancy hampshire (12)
- it support winchester (12)
- 2020 (11)
- 2022 (11)
- Microsoft Planner (11)
- hybrid cloud (11)
- internet safety (11)
- it consultancy dorset (11)
- msp (11)
- IT costs (10)
- data breach (10)
- it consultancy southampton (10)
- phishing (10)
- vulnerabilities (10)
- windows (10)
- windows 10 (10)
- Backup (9)
- bitwarden (9)
- digital (9)
- telephony (9)
- attack (8)
- communication (8)
- desk phone (8)
- education (8)
- eu (8)
- planning (8)
- software (8)
- staff (8)
- uk (8)
- Google (7)
- Hampshire (7)
- OneDrive (7)
- awards (7)
- infrastructure (7)
- mobile (7)
- offsite backup (7)
- outsource (7)
- partnership (7)
- 2019 (6)
- Apple (6)
- Bournemouth (6)
- Dorset (6)
- IT Director (6)
- Skype for Business (6)
- apps (6)
- architect (6)
- child protection (6)
- cloud storage (6)
- european union (6)
- hacks (6)
- legal (6)
- legal it (6)
- mobile phones (6)
- onsite backup (6)
- password manager (6)
- remote desktop service (6)
- usecure (6)
- virus (6)
- 3d design desktop (5)
- Azure (5)
- Desktop (5)
- ISO (5)
- News (5)
- Risk assessment (5)
- Windows 7 (5)
- brexit (5)
- designer (5)
- personal data (5)
- resources (5)
- smartphone (5)
- surrey (5)
- website (5)
- Access Management (4)
- BYOD (4)
- Case Studies (4)
- Facebook (4)
- Government (4)
- Microsoft Forms (4)
- SharePoint (4)
- VPN (4)
- WannaCry (4)
- ios (4)
- law (4)
- legacy (4)
- proactive (4)
- remote learning (4)
- 2021 (3)
- 2024 (3)
- Attacks (3)
- General (3)
- Google Drive (3)
- Help (3)
- IP (3)
- Local (3)
- Microsoft Copilot (3)
- NHS (3)
- New Forest (3)
- Tiva (3)
- Zoom (3)
- artificial intelligence (3)
- award winning (3)
- big switch off (3)
- budgets (3)
- citrix (3)
- closed cloud (3)
- ddos (3)
- digital hub (3)
- disaster recovery (3)
- guide (3)
- innovation (3)
- instagram (3)
- internet of things (3)
- meetings (3)
- sme (3)
- storage (3)
- teaching (3)
- trump (3)
- twitter (3)
- united kingdom (3)
- 2016 (2)
- 2018 (2)
- AI (2)
- CAD (2)
- ChatGPT (2)
- DR (2)
- DR planning (2)
- Environment (2)
- Firewall (2)
- GPT-4 (2)
- Gen Z (2)
- ISBA (2)
- Macs (2)
- Mr Mulligans (2)
- PaaS (2)
- Sydenhams (2)
- Thames Valley Tech & Innovation Awards (2)
- The Business Magazine (2)
- afc bournemouth (2)
- afcb (2)
- android (2)
- bcs (2)
- berkshire (2)
- broadband (2)
- camcloud (2)
- computer performance (2)
- copilot (2)
- copilot pro (2)
- digital transformation (2)
- downtime (2)
- dropbox (2)
- exhibition (2)
- finalist (2)
- legalex (2)
- london (2)
- macos (2)
- online meetings (2)
- organisation (2)
- paypal (2)
- predictions (2)
- president (2)
- serval systems (2)
- solent (2)
- strategy (2)
- us (2)
- video conferencing tools (2)
- wireless internet bournemouth (2)
- 1998 (1)
- 5G (1)
- AMD (1)
- ARM (1)
- Abbey Hill (1)
- Aldwickbury Park (1)
- BBC (1)
- BGL Company (1)
- BUNKERS! (1)
- Birchwood Park (1)
- Bourne Group (1)
- Burhill (1)
- Burhill Group (1)
- Burnout (1)
- CEO (1)
- Central South Business Awards (1)
- Cloudtango (1)
- Dorset Chamber (1)
- Go Integrator (1)
- Growth 100 (1)
- Harvey Jones Kitchens (1)
- High Growth (1)
- Hoebridge (1)
- Ignite 2018 (1)
- Ignite 2020 (1)
- Leaders (1)
- Loop (1)
- MFA (1)
- MSP Select 2024 (1)
- Market (1)
- May (1)
- Multi Factor Authentication (1)
- MyAnalytics (1)
- Ninja Warrior UK (1)
- PBX (1)
- PM (1)
- Power BI (1)
- Privacy Shield (1)
- Ramsdale Park (1)
- Redbourn (1)
- Regulation (1)
- Reid Steel (1)
- Surrey Business Awards (1)
- Tech Company of the Year (1)
- Tech Growth (1)
- Thames Valley (1)
- Thornbury (1)
- WCry (1)
- WannaCrypt (1)
- Wifi (1)
- Wycombe Heights (1)
- acquisition (1)
- ashley madison (1)
- award (1)
- b2b (1)
- bandwidth (1)
- battersea (1)
- beach (1)
- big data (1)
- bloatware (1)
- blockchain (1)
- brand (1)
- builders merchant (1)
- cambridge analytica (1)
- canada (1)
- cia (1)
- clinton (1)
- cnn (1)
- copyright (1)
- cryptocurrency (1)
- dark web (1)
- dkim (1)
- dmarc (1)
- dns (1)
- donald (1)
- dyn (1)
- east grinstead (1)
- election (1)
- equality (1)
- executive order (1)
- farnham (1)
- fax (1)
- football (1)
- gchq (1)
- grinstead (1)
- intel (1)
- intelligence (1)
- josh widdicombe (1)
- landmarks (1)
- learning (1)
- legal technology forum (1)
- machine learning (1)
- meltdown (1)
- millennials (1)
- mirai (1)
- no-deal (1)
- onsite (1)
- paper (1)
- patisserie valerie (1)
- performance reviews (1)
- pound (1)
- premier league (1)
- procrastination (1)
- reading (1)
- recruitment (1)
- research (1)
- sharefile (1)
- smishing (1)
- snowden (1)
- solent business awards (1)
- solentBA (1)
- spectre (1)
- spf (1)
- sterling (1)
- storm (1)
- talktalk (1)
- trumppresident (1)
- ukitawards (1)
- united states (1)
- usa (1)
- vault 7 (1)
- vitality stadium (1)
- whatsapp (1)
- white (1)
- white house (1)
- wikileaks (1)
- wireless internet southampton (1)
- women in business (1)
- xiongmai (1)
- year (1)