⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7
Every mailbox provider that receives your email already sends back a daily report on who has been sending as your domain. They arrive as XML attachments that nobody reads, which is a shame, because they are the only view you get of somebody impersonating your business.
Hamilton365 collects those reports, turns them into something readable, checks your DNS every day, and tells you when something changes. I read them. You get told what matters and what to do about it.
A list in your DNS of the servers allowed to send email using your domain name.
A signature added to each message that proves it really came from your domain and was not altered on the way.
A published instruction telling receiving mail servers what to do with mail claiming to be from you that fails those two checks, and asking them to report back on what they saw.
That is enough to read this page. The longer version is in SPF, DKIM and DMARC explained for business owners.
Putting a DMARC record in your DNS is a ten minute job. The part that defeats people is everything after it.
Aggregate reports arrive daily, one from each provider that received your mail, as compressed XML. A single day for a small business might be six files. Each lists sending IP addresses, message counts, and whether SPF and DKIM passed and aligned. There is no summary, no history, and nothing to tell you which entries are your accounting system and which are somebody in another country sending invoices with your name on them.
So most small businesses do one of two things. They point the reporting address at a mailbox nobody opens, or they leave the reporting tag off entirely and publish a record that reports to no one. Either way the record exists, the box is ticked, and the thing DMARC was built to show you is not being looked at by anybody.
One view per domain: how much of your mail passes, which systems are sending it, and whether each one is passing on SPF, DKIM or neither. The senders worth knowing about are the ones that were not there last month, and those are the hardest thing to spot in raw reports.
SPF, DKIM and DMARC are validated every day. When something is wrong you get the problem in plain English and the change that fixes it, rather than a score out of a hundred that you then have to interpret.
A record disappearing or being weakened, a sending source appearing that was not there yesterday, or authentication failures climbing. DNS records get edited by web developers and marketing platforms far more often than anyone expects, and usually without telling you.
Most DMARC tools want to see tens of thousands of messages before they will suggest moving to enforcement, because they were written for companies much larger than yours. A business with modest, clean, well understood mail can usually progress in weeks. The advisor explains its reasoning each time rather than handing down a verdict.
Browsable history rather than a rolling two week window. When a customer says an email never arrived, or an insurer asks what your posture was in March, there is somewhere to look.
The setting that puts your logo beside your name in some mail clients. The dashboard reports on it, it requires enforcement first, and the certificate cost makes it a later question for most small businesses. Shown, not pushed.
DMARC changed in May 2026. RFC 9989 replaced the original 2015 specification, and it is the first version of DMARC published as a standards-track standard rather than an informational document. A lot of what is on the market is still built to the old one. This is built to the new one.
The practical difference is how a policy gets rolled out. The old specification let you apply your policy to a percentage of your mail and raise it over time. That has been removed from the standard. In its place is a testing mode, and it is worth understanding properly, because the name invites exactly the wrong assumption.
Switching testing on applies the policy one step softer than the one you published. Reject behaves as quarantine. Quarantine behaves as none. So a domain publishing reject with testing switched on is having its failing mail put in junk folders right now. That is a genuinely useful place to stand for a few weeks, because junk is recoverable and rejection is not, but it is a real setting with real effects.
Anyone who describes it to you as reporting only has misread the specification, and the difference between those two readings is whether you think your mail is being touched. Your dashboard shows which setting you are actually on.
RFC 9989 was published in May 2026 and obsoletes RFC 7489. The three policy values, none, quarantine and reject, are unchanged from the original.
Four steps, and only one of them needs anything from you.
Nothing changes on your side and nothing is published yet. This is the part where the reporting address is created and the domain is added.
It starts in monitor-only mode and sends the reports to Hamilton365. Nothing is enforced at this point, so nothing can break. I can publish it if you have access to give, or hand you the exact line to pass to whoever looks after your DNS.
The dashboard fills in as providers report back. The first fortnight is mostly discovery, and there is nearly always at least one sender nobody remembered. The monthly and annual ones take longer to appear, which is the real reason this is not a two week exercise.
Quarantine first, then reject, guided by what the reports show rather than by a calendar. A business with a handful of senders is often a few weeks. One that has picked up tools over ten years takes longer, and the length is set by how many things turn out to be sending as you, not by how hard the changes are.
At enforcement, DMARC stops somebody sending email that claims to come from your exact domain. That is a real and common attack and it is worth closing properly.
It does not stop three other things, and any tool that suggests otherwise is overselling itself.
Somebody registers a near miss of your name and sends from that instead. Their DMARC passes, because it is genuinely their domain. Yours is not involved.
The sender's name reads as yours, but the address underneath is a free webmail account. Nothing about your DNS has any say in what a stranger types into the name field.
That mail is properly authenticated, because it really is from you. DMARC will pass it, correctly, and it is the single most expensive kind of email fraud in Australia.
Monitoring closes the first and gives you early warning of some of the second. If you are dealing with the third right now, start at business email compromise response instead and come back to this afterwards. Hardening comes after containment, not instead of it.
Worth being clear about, particularly if you are in a regulated profession and somebody will eventually ask you.
Hamilton365 never sees the contents of your email through this service, because that information is not in the reports and never has been. If you are a law firm, accounting practice, conveyancer or real estate agency working through what your wider obligations look like, the Privacy Act readiness assessment covers the tenant rather than the DNS.
Every account needs a password and a code from an authenticator app. There is no option to turn that off, for you or for me, because an account holding a view of your mail flow is worth protecting properly and optional multi-factor authentication is the kind that never gets switched on.
You can choose to trust a browser for 30 days so you are not typing a code on every visit.
Per domain, GST inclusive, and all three figures are on this page so you are never guessing what the next step up costs. The difference between the first two is not how much you care about being spoofed, it is how many places your mail leaves from.
You read the dashboard. I set it up and keep it running.
$29
per domain per month, GST inclusive
or $319 a year, which is eleven months for twelve
Best for
Sole traders and small teams whose mail leaves from one or two places, typically Microsoft 365 plus something like Xero. Few sources means few surprises, and the dashboard is usually enough on its own.
I read the reports and make the changes. You get told what happened.
$99
per domain per month, GST inclusive
three month minimum, then month to month
Best for
Businesses sending campaigns, newsletters, statements or booking confirmations, where mail leaves from several platforms and the list keeps growing. More sources means more that can change without anyone noticing, and that is the part that takes a person.
For the ones you own and do not send from.
$12
per domain per month, GST inclusive
added to either tier
Best for
Anyone who owns more than one domain, which is most businesses once they count. Added to either tier, and the price is lower because a domain that sends nothing takes almost no watching.
If your domain has been running for years and has picked up senders along the way, the work of finding all of them and fixing alignment on each one is a project rather than a subscription. It is quoted after the $299 Email Security Health Check, because the price depends entirely on how many senders turn up and any number before then would be a guess.
A domain starting from nothing usually does not need that. It goes straight onto monitoring and moves up from there.
Tell me your domain and I will read its DNS records before I reply, so the first thing you get back says something about your situation rather than mine.
Already a customer? Sign in to your dashboard
Questions first? Call 0403 401 250 or email jamie@hamilton365.com.au