Dmarc Overview

DMARC+ use cases

Worked examples that combine the DMARC+ features. Each is a short recipe.

Onboard 20 domains

Goal: get every domain reporting into DMARC+ within a couple of weeks.

  1. Build an inventory and split it into sending and parked domains.
  2. Add all domains in DMARC+ > Domains and set criticality. Group related domains.
  3. Publish monitoring records for all. Use managed records so later policy changes need no DNS work.
  4. Publish reject records on parked domains right away.
  5. Two days later, use the warning icon on the Domains page to find domains not reporting.
  6. Track the rest with the weekly report.

See DMARC for multiple domains.

Find shadow senders

Goal: find services sending as you that IT does not know about.

  1. Set the Dashboard to the last 30 days.
  2. Open Report Sources and list every source.
  3. For each unfamiliar source open the Aggregate Reports Explorer and read the PTR name and volume.
  4. Ask the business teams. Classify each as approved, needs fixing, or unauthorized.
  5. Fix approved sources. See Managing third-party senders.

Tip: repeat monthly. New tools appear constantly.

Stop spoofing of a parked domain

  1. Add the domain with Parked Domain on.
  2. Publish v=spf1 -all and a p=reject DMARC record with your DMARC+ address.
  3. Check both with Tools > Domain Scanner.
  4. Review the Explorer weekly. Any volume is spoofing.
  5. Optionally raise a takedown for domains that are being abused, using your normal process.

Report to the board

  1. Use a formatted report. Choose the new layout template for the last 30 days, or schedule it monthly or quarterly.
  2. Include the number of domains, the share enforced, the pass rate and the trend.
  3. State clearly what each policy means, and which domains are still at none.
  4. If you use the Hunto security score, cite the email health factor. See How DMARC+ connects to other Hunto features.

Chase failing senders

  1. In the Explorer, filter to DMARC failing and sort by volume.
  2. For each legitimate failing sender, create a task in Hunto Tasks with the domain, sender, IP, volume and the fix required.
  3. Assign it to the sender's owner, with a due date before your next policy step.

Note: DMARC+ does not create tasks by itself today. Create them manually.

Prepare for a mail migration

  1. Before the move, list all senders from the Report Sources.
  2. Set up authentication at the new provider first.
  3. Move gradually, keep the policy where it is, and watch failures daily for a week.
  4. Only then remove the old provider from SPF.

Check a partner or acquisition

  1. Use Tools > Domain Scanner on their domain.
  2. Note missing or weak SPF, DKIM and DMARC.
  3. Add the domain to DMARC+ if you will be sending as it.