⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Written for Australian small business

DMARC in Australia, and what is actually required

No Australian law tells a private business to publish a DMARC record. Plenty of other things do. Here is who asks, what each one is really asking for, what the government guidance says, and the two places that guidance is now behind the standard.

Free, no account, and the domain you check is not recorded.

Is DMARC mandatory in Australia?

For a private Australian business, no. There is no statute, no regulator and no penalty. If somebody has told you otherwise, they are selling something, and this page sells something too, so it is worth saying plainly before anything else.

What has happened instead is that five separate parties now ask for it, none of them a lawmaker, and between them they cover most businesses that send email to anyone outside their own office. The practical effect is close to a requirement. The important part, and the part almost every page on this subject skips, is that they are not all asking for the same thing.

A record at p=none satisfies some of them and not others. That single distinction is where most of the trouble in this area comes from.

Who asks Australian businesses for DMARC

The parties that ask Australian businesses for DMARC, and what each one requires
Who is askingWhat they wantWorth knowing
Google, Yahoo and MicrosoftA DMARC record, if you send bulkTheir bulk sender rules apply above a daily volume threshold. A record at p=none satisfies the DMARC line item, which is why so many domains published one and stopped.
Cyber insurance renewalsUsually enforcement, if you read the wordingQuestionnaires tend to ask whether DMARC is implemented or enforced rather than whether a record exists. The difference is one people answer quickly and get examined on slowly.
Larger customers and government suppliersVaries, and it is usually in the contractSupplier security questionnaires increasingly carry an email authentication line. Commonwealth entities work to their own rules, which are stricter than anything asked of a small business.
SMB1001 certificationEmail authentication, at the level you certify toA five level standard published by Dynamic Standards International rather than by government. Confirm the current wording for your tier with your certifier, because the levels are revised.
Australian Signals Directorate guidanceA record immediately, then enforcementRecommended rather than required for private business. Its stated best practice is quarantine or reject, covering subdomains, with the reports actually being read.

If your domain publishes a record and you have never seen a report, you are answering yes to the first row and no to the rest of them.

Related

Not sure which of those describes your domain? The free DMARC record checker on this site reads your DMARC, SPF and DKIM in one pass and tells you what a receiver would currently do with a forged message claiming to be from you. It takes a few seconds, asks for nothing, and stores nothing.

What the Australian government guidance says

The Australian Signals Directorate publishes email hardening guidance on cyber.gov.au, and the publication that covers this is called How to combat fake emails. Its instruction is unambiguous: implement DMARC immediately, even if only in monitoring mode, regardless of what else you have in place.

Its stated best practice end state is a DMARC record at your root domain that quarantines or rejects everything failing authentication, applies to subdomains as well, and publishes a reporting address whose reports are, in its own words, captured into a system and reviewed regularly. It also asks for a hard fail SPF record on every domain and subdomain, including the ones that send no mail at all.

The correction most pages get wrong

DMARC is not part of the Essential Eight. The eight are patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Email authentication is not among them and never has been. Doing DMARC properly does not move you up an Essential Eight maturity level, and if a proposal tells you it will, that proposal has not read the maturity model.

That does not make DMARC less important, and the guidance that does cover it is more direct about DMARC than the Essential Eight is about most of its own items. It just means the two are separate pieces of work, and a business being assessed against one is not being assessed against the other.

Two places that guidance is now behind the standard

How to combat fake emails was last updated in October 2021. DMARC changed in May 2026, when RFC 9989 obsoleted RFC 7489 and became the first standards-track version of the specification. The direction of the advice is unchanged and still correct. Two mechanical details in it are not, and both show up in the example records it gives you to copy.

  • The percentage tag no longer exists

    The worked examples use pct=100, and the guidance describes rolling a policy out to a small percentage of mail first. Appendix A.6 of RFC 9989 is titled Removal of the "pct" Tag. If your record still carries it, it is doing nothing at all. Step the policy itself instead, from none to quarantine to reject.

  • Finding your policy no longer relies only on a public suffix list

    The guidance describes receivers making a maximum of two lookups and consulting a public suffix list to find your organisational domain. RFC 9989 supplements that with a DNS Tree Walk. In practice this rarely changes the record you publish, but it does change what happens on deeper subdomains, and it is why np is worth knowing about now.

One thing in that publication has not aged at all, and it is the most useful sentence in it. If your reports are going to a domain other than your own, the receiving domain has to publish a record agreeing to accept them. Miss it and the reports are silently never sent. No error is raised, nothing bounces, and the dashboard simply stays empty while everyone assumes it is working.

Anything different about a .com.au domain?

The records are identical. There is no Australian variant of DMARC, and a record that works on a .com works on a .com.au unchanged.

Two things are worth knowing anyway. The first is that com.au is a public suffix, so your record belongs at your own domain and there is no useful level above it. The second is parked domains, and it catches Australian businesses more than most, because registering the .com.au and the .com and sometimes the .net.au is normal practice here.

A domain you own and never send from is not protected by the one you do send from. Until each of them publishes a record saying it sends nothing, every one of them remains available to anyone who wants to invoice your customers under a name they recognise. They are the cheapest records to publish and the ones most often left out.

Questions about DMARC in Australia

Getting an Australian domain to reject

Publishing the record is the easy half and you can do it yourself this afternoon. The half that stalls is reading what comes back, working out whether an unfamiliar sending host is your new booking system or somebody in another country, and being confident enough to step the policy. That is what the monitoring service does, from $29 per domain per month, GST inclusive.

Brisbane based, and DMARC work is remote, so the domain being in Perth or Hobart changes nothing.