Dmarc Overview

DMARC for multiple domains and parked domains

Organizations often own dozens of domains: the main brand, product names, regional domains and defensive registrations. This page shows how to bring all of them under DMARC+ efficiently, and how to protect domains that never send mail.

Plan the inventory

  1. List every domain you own, from your registrar accounts and from Hunto's asset inventory.
  2. Split them into two sets.
Set Description Target policy
Sending Domains and subdomains that send mail Monitor, fix, then enforce
Parked Domains that never send mail Enforce straight away
  1. Give each domain a criticality: High for the main brand and any domain that sends customer mail, Medium for internal or regional, Low for the rest.

Onboard in waves

For 20 or more domains, avoid doing everything at once.

Wave Domains Goal
1 Parked domains Quick win. Enforce immediately.
2 One or two low-risk sending domains Learn the process
3 The rest of the sending domains, in batches of 5 to 10 Repeat the rollout
4 The main brand domain Enforce last, with the most preparation

For each domain: add it on DMARC+ > Domains, publish the monitoring record, and check that the warning icon disappears after reports flow.

Tip: put related domains in a domain group so you can filter the Dashboard by group and report by business unit.

Use managed records at scale

With managed records you publish a CNAME once for each domain and then change policies from DMARC+. This removes repeated DNS work for each policy step. See Managed record tools.

Track progress

Question Where
Which domains have no DMARC record? Domains page, cards with a dash for policy
Which domains do not send reports to DMARC+? Domains page, cards with the warning icon
Which domains are enforced? Domains page policy, or the weekly report policy counts
Which have the worst pass rate? Dashboard Domains table sorted by DMARC Compliance

Parked domains

A parked domain has no legitimate mail. Attackers like it because it looks trustworthy. Publish:

Record Value Effect
SPF v=spf1 -all No server is allowed to send
DMARC v=DMARC1; p=reject; rua=mailto:<your DMARC+ address> Receivers reject mail claiming to be from the domain
Null MX (optional) An MX record that declares the domain accepts no mail Stops mail being delivered to the domain
DKIM Not needed

Steps:

  1. Add the domain in DMARC+ and turn on Parked Domain.
  2. Generate a p=reject record in the DMARC Generator, or in Managed DMARC.
  3. Publish the SPF record above at the domain.
  4. Check with Tools > Domain Scanner.
  5. Watch the Aggregate Reports Explorer. Any volume at all is unauthorized, so review it.

Note: if you point rua at an address in a different domain from the one you monitor, that other domain must publish a record authorizing your domain to send it reports. Use the addresses that DMARC+ gives you unless you have a reason not to.

Tip: use the same parked-domain record set for every registered-but-unused domain, including typo variants of your brand.

Subdomains

A subdomain with no _dmarc record inherits the policy of its parent. Use sp=reject on the parent when no subdomain sends mail, or publish a specific record for any subdomain that does.