What is DMARC and why do we need it?

15th May 2025

What is DMARC?

DMARC is basically the bouncer for your company’s email.

When your organisation sends an email, you want the receiver to know it’s really from you and not from some scammer pretending to be you.

DMARC is a rulebook you publish that tells other mail servers:

  1. How to check if an email claiming to be from you is legit
    (It uses two older checks behind the scenes: SPF and DKIM.)

  2. What to do if an email fails those checks

    • Let it through anyway – Not good you don’t want emails not from you arriving in your clients Inbox. Known as p=none

    • Put it in spam – Also not good, yes better than going direct into a clients Inbox but if they check their spam regularly they will still get the email that’s not from you. Known as p=quarantine

    • Or deny/block it – If an email is not genuinely from you then it needs to be denied/blocked so your clients don’t get it. Known as p=reject

  3. Where to send reports about who’s trying to spoof your domain
    So you can see if someone is out there impersonating your brand.

Think of it as:
“Here are my security guards (SPF/DKIM). If someone fails the ID check, here’s how I want you to handle them, and by the way, please send me a daily report.”

So DMARC is a simple but mighty way to stop people sending dodgy emails pretending to be you.

Why do we need it?

Because without DMARC, your email domain is basically a house with the front door wide open and a sign saying, “Please don’t rob me.”

Here’s the easy answer:

1. Stops scammers pretending to be you

Anyone can forge the “From” address on an email. Without DMARC, there’s nothing stopping someone sending fake emails that look like they came from your domain.
DMARC tells receiving servers how to handle fakes, so most of them get blocked or dumped into spam/junk.

If someone sent a fake Invoice to your clients, or even worse they intercepted a genuine Invoice you sent and changed the bank details on that invoice and then sent it on to your client this could result in your client paying someone else. This is not something you want to happen.

2. Protects your brand

If scammers send emails pretending to be you, your company looks unprofessional or — worse — untrustworthy. DMARC helps you avoid that PR nightmare.

3. Improves your email deliverability

Ironically, not having DMARC can make even your real emails look suspicious.
Having DMARC set up correctly makes inbox providers like Microsoft, Google, and everyone else more confident you’re genuine — so your emails land in inboxes instead of spam folders or bouncing back.

4. Gives visibility into what’s happening with your domain

DMARC’s reports show you:

  • who’s sending email from your domain,

  • who’s trying to,

  • and whether your own systems are set up correctly.

You can’t fix what you can’t see.

5. It’s becoming a requirement

Google, Yahoo and Microsoft already expect DMARC from bulk senders. Others will be following soon.

Soon “no DMARC” will be the email equivalent of “no seatbelt”.


In short:
DMARC keeps the bad guys out, keeps your real mail flowing, and stops your domain from becoming a playground for scammers.

DMARC is only one element of protecting your domain, the others are:

You need all three setup and configured correctly for full authentication of your domain.

SPF + DKIM + DMARC are all required for FULL AUTHENTICATION of your email system.