DMARC+ use cases
Worked examples that combine the DMARC+ features. Each is a short recipe.
Onboard 20 domains
Goal: get every domain reporting into DMARC+ within a couple of weeks.
- Build an inventory and split it into sending and parked domains.
- Add all domains in DMARC+ > Domains and set criticality. Group related domains.
- Publish monitoring records for all. Use managed records so later policy changes need no DNS work.
- Publish reject records on parked domains right away.
- Two days later, use the warning icon on the Domains page to find domains not reporting.
- Track the rest with the weekly report.
See DMARC for multiple domains.
Find shadow senders
Goal: find services sending as you that IT does not know about.
- Set the Dashboard to the last 30 days.
- Open Report Sources and list every source.
- For each unfamiliar source open the Aggregate Reports Explorer and read the PTR name and volume.
- Ask the business teams. Classify each as approved, needs fixing, or unauthorized.
- Fix approved sources. See Managing third-party senders.
Tip: repeat monthly. New tools appear constantly.
Stop spoofing of a parked domain
- Add the domain with Parked Domain on.
- Publish
v=spf1 -alland ap=rejectDMARC record with your DMARC+ address. - Check both with Tools > Domain Scanner.
- Review the Explorer weekly. Any volume is spoofing.
- Optionally raise a takedown for domains that are being abused, using your normal process.
Report to the board
- Use a formatted report. Choose the new layout template for the last 30 days, or schedule it monthly or quarterly.
- Include the number of domains, the share enforced, the pass rate and the trend.
- State clearly what each policy means, and which domains are still at
none. - If you use the Hunto security score, cite the email health factor. See How DMARC+ connects to other Hunto features.
Chase failing senders
- In the Explorer, filter to DMARC failing and sort by volume.
- For each legitimate failing sender, create a task in Hunto Tasks with the domain, sender, IP, volume and the fix required.
- Assign it to the sender's owner, with a due date before your next policy step.
Note: DMARC+ does not create tasks by itself today. Create them manually.
Prepare for a mail migration
- Before the move, list all senders from the Report Sources.
- Set up authentication at the new provider first.
- Move gradually, keep the policy where it is, and watch failures daily for a week.
- Only then remove the old provider from SPF.
Check a partner or acquisition
- Use Tools > Domain Scanner on their domain.
- Note missing or weak SPF, DKIM and DMARC.
- Add the domain to DMARC+ if you will be sending as it.