When someone receives an email from your business, the address in the From field looks like proof of who sent it. It is not proof on its own.
Without suitable email authentication, another system may be able to send a message that uses your exact domain in the visible From address. This is called exact-domain spoofing.
What DMARC is
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It works with SPF and DKIM.
SPF
SPF checks whether the server connecting to the recipient is authorised for the domain used in the message’s technical return path. That technical domain may differ from the address a person sees in the From field.
DKIM
DKIM adds a cryptographic signature to an email. The receiving system can check whether the signature is valid and which domain is associated with it.
DMARC
DMARC connects authentication to the domain visible in the From address. A message passes DMARC when SPF or DKIM passes and the passing domain aligns with the visible From domain.
The domain owner can also publish a policy requesting how receiving systems treat messages that fail.
The three DMARC policy levels
Monitoring
The p=none policy observes results without requesting that failing messages be quarantined or rejected. It is normally the starting point while legitimate services are identified.
Quarantine
The p=quarantine policy asks receiving systems to treat failing messages with additional suspicion. A receiver may place the message outside the normal inbox.
Reject
The p=reject policy asks receiving systems to refuse messages that fail DMARC.
These are requested policies. Each receiving system may still apply its own rules. A published policy is not a universal delivery guarantee.
Why monitoring matters before enforcement
Businesses often send through Microsoft 365 or Google Workspace, accounting software, websites, marketing platforms, helpdesks, payroll systems and monitoring services.
Some send daily. Others send only at month-end or during a particular process. Moving directly to enforcement without identifying these legitimate senders can affect genuine email.
A safer process is to collect report evidence, identify services, correct authentication problems and progress policy carefully.
What aggregate reports show
Participating receiving systems can report sending sources, message counts, SPF and DKIM results, alignment and the action reported by the receiver.
Reports help identify known services, unfamiliar sources and authentication gaps. They do not provide a copy of every email or identify the person behind an IP address.
What DMARC can help with
- See which services are observed sending email using the domain
- Find legitimate senders with SPF or DKIM alignment problems
- Reduce successful exact-domain spoofing
- Publish a handling request for failures
- Track changes in sending sources and authentication results
What DMARC does not do
DMARC does not inspect content, scan attachments, replace an inbound security gateway, stop lookalike domains, stop display-name impersonation, protect a compromised mailbox, prove an authenticated message is safe, guarantee inbox delivery, guarantee POPIA compliance or prevent every form of phishing and invoice fraud.
Those risks need other controls, including account security, filtering, staff processes, backup and incident response.
Why DMARC needs ongoing management
Business email systems change. A new invoicing platform, marketing service or website supplier may start sending. An old service may be retired or a provider may change its configuration.
Ongoing management helps review new sources, investigate failures, correct SPF or DKIM issues, maintain a sender inventory, assess policy changes and continue monitoring after a stronger policy is reached.
A practical managed process
- Assess. Review published DMARC, SPF, DKIM and mail-routing signals, then confirm ownership of DNS and mail decisions.
- Observe. Collect aggregate reports across normal business cycles.
- Remediate. Work with the domain owner and providers to correct authentication and alignment.
- Progress. Change policy when evidence shows legitimate mail is aligned and remaining risks are understood.
- Continue monitoring. Keep reviewing the domain as authorised services change.
The standard works the same for a South African domain as elsewhere. Local providers can help coordinate access, configuration, reporting and decisions when responsibilities are clear.
Managed DMARC is delivered by Kwik Support and powered by Vigil. The exact delivery and commercial scope are confirmed for each customer. Read about the Managed DMARC service.
A sensible next step
Talk to Kwik Support
Tell us about the current setup, the problem you are trying to solve and the outcome your business needs.
Talk to Kwik Support