New Security Awareness Training date to be announced soon!

16 Sep 2026

What is DMARC and Why Does Your Business Need It?

Jay Ball
Chief Executive Officer

Somebody can send an email that looks exactly like it came from your business. Your domain, your name, your reputation. It lands in a customer's inbox asking them to pay an invoice to a new bank account, and there is nothing about it that looks wrong. That is spoofing, and DMARC is the mechanism that stops it.

DMARC in one paragraph

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a small record you publish in your domain's DNS. It does two jobs. First, it tells every receiving mail server in the world what to do with email that claims to be from your domain but fails authentication: deliver it anyway, send it to junk, or reject it outright. Second, it makes those servers report back to you, so you can see exactly who is sending email as your domain, legitimate or not.

DMARC sits on top of two older checks, SPF and DKIM, which do the actual verifying. If you want the full picture of how the three work together, read SPF, DKIM and DMARC Explained in Plain English.

Why it matters more than it used to

Two reasons.

  • The big providers now expect it. Since 2024, Google, Yahoo and Microsoft have tightened requirements for inbound mail. Domains without DMARC increasingly find their legitimate email treated as suspicious. If your deliverability has slipped and you can't explain why, this is the first place to look. Our guide on why emails go to spam covers the other causes.
  • Invoice fraud runs on spoofing. Criminals don't need to hack your systems to impersonate you. Without an enforced DMARC policy, they can send as your exact domain and most receiving servers will let it through. UK businesses lose millions to payment diversion fraud every year, and the spoofed invoice is its favourite vehicle.

The three policy levels

  • p=none. Monitoring only. Failing mail is still delivered, but you receive reports. The right place to start, the wrong place to stay.
  • p=quarantine. Failing mail goes to junk.
  • p=reject. Failing mail is refused entirely. This is full protection: nobody can send as your domain and reach an inbox.

Here is the uncomfortable statistic from our own audits: most businesses that have DMARC at all are stuck at p=none, often for years. They believe they're protected. They're not. The record is there, the reports pile up unread, and spoofed mail still gets delivered.

What the reports actually tell you

DMARC reports arrive daily as XML files from every major mail provider. Decoded, they show every IP address and service sending email as your domain. Businesses are routinely surprised by what turns up: the CRM nobody registered, the invoicing tool a supplier set up, a marketing platform from three years ago, and sometimes senders in countries you've never traded with. You cannot safely move to reject until every legitimate sender in that list passes authentication, which is why the reports matter and why ignoring them stalls the whole project.

How to get it done

If you run Microsoft 365, our step-by-step DMARC setup guide walks through the whole thing, from SPF and DKIM to publishing the record. Budget a few weeks of monitoring before you enforce.

If you'd rather it were simply handled, Flo Verified Mail is our managed DMARC service: we set everything up, check the reports every day, and take your domain to full enforcement so your email arrives and nobody else can send as you. It is part of how we think about email deliverability as a whole, not a box-ticking exercise.

No items found.

Download ‘Your First 60 Days with Microsoft Copilot’ Guide

A practical, week-by-week setup guide for paid Microsoft 365 Copilot users. Personalisation, automations, agents and the daily habits that turn a licence into real time saved.
Get your free guide now!
The Content Hub
Stay ahead with news, blogs, events, and customer case studies