Why this is more than three DNS records

Publishing the records is the quick part. The real work sits in the question of who legitimately sends under the domain: the ERP, the newsletter service, the ticket system, multifunction devices, the external payroll provider. Every forgotten source means lost mail after enforcement. That is why every DMARC project of mine starts with an inventory of the actual sending sources from DMARC reports and mail logs, not with editing the DNS zone.

Services

  • Sending source inventoryIdentifying every system that sends under your domains, the forgotten ones included; from reports, logs and tenant evaluations.
  • Record designSPF within the lookup limit, DKIM signing per sending source, DMARC with a sensible alignment strategy, subdomains and parked domains included.
  • Staged plan to p=rejectTightening via none, quarantine and pct stages, with report evaluation before each step and defined abort criteria.
  • The hard casesForwarding, mailing lists, gateways in front of Microsoft 365, ARC sealing: the cases DMARC projects usually fail on.

Real-world examples