DMARC for multiple domains and parked domains
Organizations often own dozens of domains: the main brand, product names, regional domains and defensive registrations. This page shows how to bring all of them under DMARC+ efficiently, and how to protect domains that never send mail.
Plan the inventory
- List every domain you own, from your registrar accounts and from Hunto's asset inventory.
- Split them into two sets.
| Set | Description | Target policy |
|---|---|---|
| Sending | Domains and subdomains that send mail | Monitor, fix, then enforce |
| Parked | Domains that never send mail | Enforce straight away |
- Give each domain a criticality: High for the main brand and any domain that sends customer mail, Medium for internal or regional, Low for the rest.
Onboard in waves
For 20 or more domains, avoid doing everything at once.
| Wave | Domains | Goal |
|---|---|---|
| 1 | Parked domains | Quick win. Enforce immediately. |
| 2 | One or two low-risk sending domains | Learn the process |
| 3 | The rest of the sending domains, in batches of 5 to 10 | Repeat the rollout |
| 4 | The main brand domain | Enforce last, with the most preparation |
For each domain: add it on DMARC+ > Domains, publish the monitoring record, and check that the warning icon disappears after reports flow.
Tip: put related domains in a domain group so you can filter the Dashboard by group and report by business unit.
Use managed records at scale
With managed records you publish a CNAME once for each domain and then change policies from DMARC+. This removes repeated DNS work for each policy step. See Managed record tools.
Track progress
| Question | Where |
|---|---|
| Which domains have no DMARC record? | Domains page, cards with a dash for policy |
| Which domains do not send reports to DMARC+? | Domains page, cards with the warning icon |
| Which domains are enforced? | Domains page policy, or the weekly report policy counts |
| Which have the worst pass rate? | Dashboard Domains table sorted by DMARC Compliance |
Parked domains
A parked domain has no legitimate mail. Attackers like it because it looks trustworthy. Publish:
| Record | Value | Effect |
|---|---|---|
| SPF | v=spf1 -all |
No server is allowed to send |
| DMARC | v=DMARC1; p=reject; rua=mailto:<your DMARC+ address> |
Receivers reject mail claiming to be from the domain |
| Null MX (optional) | An MX record that declares the domain accepts no mail | Stops mail being delivered to the domain |
| DKIM | Not needed |
Steps:
- Add the domain in DMARC+ and turn on Parked Domain.
- Generate a
p=rejectrecord in the DMARC Generator, or in Managed DMARC. - Publish the SPF record above at the domain.
- Check with Tools > Domain Scanner.
- Watch the Aggregate Reports Explorer. Any volume at all is unauthorized, so review it.
Note: if you point rua at an address in a different domain from the one you monitor, that other domain must publish a record authorizing your domain to send it reports. Use the addresses that DMARC+ gives you unless you have a reason not to.
Tip: use the same parked-domain record set for every registered-but-unused domain, including typo variants of your brand.
Subdomains
A subdomain with no _dmarc record inherits the policy of its parent. Use sp=reject on the parent when no subdomain sends mail, or publish a specific record for any subdomain that does.