What Is DMARC and Why Your Brisbane Business Needs It
By Jamie Hamilton · Published
If you send email from your own domain, anyone in the world can send email that appears to come from it too. Nothing stops them, nothing warns you, and the person receiving it has no reliable way to tell the difference. DMARC is the record that changes that.
What DMARC is
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is a line of text published in your domain’s DNS that does two jobs at once. It tells every receiving mail server in the world what you want done with a message that claims to be from you and fails authentication, and it asks those servers to send you a daily summary of what they saw.
Without it, each receiver decides for itself, and the decision most of them reach is to deliver. There is no default policy protecting a domain that has not published one.
What a DMARC record actually looks like
It is one TXT record, published at the name _dmarc in front of your domain, and it is a list of tags separated by semicolons. A typical one reads v=DMARC1; p=reject; rua=mailto:reports@yourbusiness.com.au.
Only two tags are required and only one of them decides whether you are protected. The v tag names the version and is always DMARC1. The p tag is the policy, and it is the whole of your protection. The rua tag is where reports go, and while it is technically optional, leaving it out means receivers are instructed not to generate reports for your domain at all.
That combination, a policy with no reporting address, is the single most common state on Australian small business domains. It reads as configured to anybody who glances at it, asks nothing of receivers, and produces no information.
How the three records fit together
SPF is a list of the servers allowed to send on your behalf. DKIM puts a cryptographic signature on each message so a receiver can tell it was not altered on the way, and that check survives being forwarded where SPF does not.
Neither of them is connected to the address your reader actually sees in the From line, and that is the gap DMARC closes. It requires the domain that passed SPF or DKIM to match the visible sender, then says what should happen when nothing matches: deliver it anyway, send it to junk, or refuse it.
What happens when a message arrives
Worth walking through once, because it makes the rest obvious. A message arrives at a receiving server claiming to be from your domain.
- •The server checks SPF: was the sending server on your published list?
- •It checks DKIM: is there a valid signature, and does the key in your DNS verify it?
- •It checks alignment: does the domain that passed either check match the domain in the From line the reader will see?
- •If either SPF or DKIM passed and aligned, DMARC passes and the message is treated as genuinely yours.
- •If neither did, the server looks up your policy and does what it says.
The last line is where everything is decided. A forged message fails the first three steps every time, because the attacker cannot pass SPF or DKIM for a domain they do not control. What happens next depends entirely on what your record tells the server to do.
The three policies
| Policy | What receivers are asked to do | Where it belongs |
|---|---|---|
| p=none | Report, and take no action. Failing mail is delivered normally. | A first step, while you find out what legitimately sends as you |
| p=quarantine | Send failing mail to the junk folder. | A staging post on the way to reject, for a few weeks |
| p=reject | Refuse failing mail outright, so it is never delivered. | The finished state, and where a domain should end up |
Quarantine is a poor place to stop, because junk folders get read and a convincing invoice found in junk is still a convincing invoice. Reject is the only setting where a forged message does not reach the person you are trying to protect.
Why it matters for your business
Without DMARC a scammer can send a phishing email that matches your domain exactly, and your clients get fake invoices that read like yours. The reputation damage lands on you afterwards, not on them. I have seen Brisbane businesses lose thousands of dollars because a client paid a spoofed invoice in good faith.
There is a second reason that has arrived more recently. Google, Yahoo and Microsoft now require DMARC of bulk senders, cyber insurance questionnaires ask about it at renewal, and supplier security reviews have started including it. A domain with no record increasingly fails somebody’s form, and a record at p=none fails the ones that ask whether DMARC is enforced rather than whether it exists.
What DMARC does not do
Being clear about this is worth more than another paragraph of why it matters, because the gaps are where the losses actually happen.
- •It does not stop a look-alike domain. A name one character different from yours belongs to whoever registered it, and your policy has no authority over somebody else’s domain.
- •It does not stop display name spoofing. The name shown beside an address is free text, and on a phone the address itself is often hidden.
- •It does not help if a real mailbox is compromised, because that mail authenticates perfectly. It genuinely is yours.
- •It does not guarantee your mail reaches the inbox. Authentication removes an obstacle to good delivery; reputation and content still decide the rest.
Enforcement is still the single highest value thing you can do, because it removes the cheapest and most convincing version of the attack, and that is the version that scales to thousands of messages.
What to do about it
Start by finding out what you already publish, because plenty of domains have something and very few have it finished. No DMARC record means no protection at all. A policy reading p=none means monitoring mode, so a forged message is still delivered. Reject is the state worth aiming for.
The free checker on this site reads your DMARC, SPF and DKIM in one pass and grades what a receiver would actually do with a forged message claiming to be you. No account, and nothing about the domain you check is stored.
Free DMARC record checker →Getting there without breaking your own mail
Publishing the record is a ten minute job. The part that takes time is working out everything that legitimately sends in your name before you switch enforcement on, because Microsoft 365 is rarely the only one. Marketing platforms, CRMs and accounting software all send as you, and each one nobody knew about is a system that stops working the day the policy moves to reject.
That is what the reports are for, and it is why the order is publish, then read, then enforce, rather than publish and enforce. The systems that send monthly or quarterly only appear in a report when they send, so the picture takes weeks to complete.
The Email Security Health Check reads what you have now and gives you the DNS records to paste in. If you would rather somebody read the reports every month instead of once, that is what managed DMARC monitoring does, from $29 per domain per month GST inclusive.
Frequently asked questions
What is DMARC in simple terms?
It is one line of text published in your domain name records that tells every receiving mail server in the world what to do with a message that claims to be from your business but cannot prove it. It also asks those servers to send you a daily report of what they saw. Without it, each receiver decides for itself, and most of them deliver the message.
How does DMARC actually work?
When a message arrives claiming to be from your domain, the receiving server checks whether it came from a server on your SPF list, whether it carries a valid DKIM signature, and whether either of those matches the address shown in the From line. If either check passes and matches, DMARC passes. If neither does, the server reads your published policy and either delivers the message, sends it to junk, or refuses it.
What is the difference between p=none, p=quarantine and p=reject?
They are the three settings for your DMARC policy. None asks receivers to report and take no action, so failing mail is still delivered normally and you are not protected. Quarantine asks them to put failing mail in the junk folder. Reject asks them to refuse it outright so it is never delivered at all. None is where you start, and reject is the only one where a forged message does not reach your customer.
Is DMARC required in Australia?
No Australian law requires a private business to publish a DMARC record. In practice several other things ask for it: Google, Yahoo and Microsoft require it of bulk senders, cyber insurance questionnaires ask about it at renewal, larger customers ask in procurement, and the Australian Signals Directorate recommends it for every organisation. Commonwealth entities work to stricter rules of their own.
How long does DMARC take to set up?
Publishing the record takes about ten minutes. Getting to enforcement safely usually takes weeks, and the time goes into finding every system that legitimately sends in your name before you switch it on. That list is longer than most businesses expect and rarely written down anywhere, which is why the reports have to run for a while first.
Will DMARC stop all spoofed emails?
It stops mail forging your exact domain, once the policy is at reject. It does not stop somebody registering a look-alike domain, because that domain is theirs rather than yours, and it does not stop a display name being set to your business name on a message sent from an unrelated address. It also cannot help if a real mailbox of yours has been compromised, because that mail is genuinely yours and authenticates normally.
Do I need DMARC if I only send a few emails a week?
Volume is not the thing that decides it. Your domain can be forged whether you send a thousand messages a day or three, and the number that matters is how many people would act on an invoice appearing to come from you. A small business with a handful of regular clients who pay large invoices is a better target than a large one with many small transactions.