DMARC enforcement should follow evidence that legitimate mail aligns. Publishing reject before identifying senders can interrupt business communication.
Inventory before policy
List every service that sends with the domain: workforce mail, applications, support, ecommerce, CRM, campaigns and legacy systems. Capture example headers and owners for each source.
Validate aligned authentication
A message passes DMARC when aligned SPF or aligned DKIM succeeds. Test representative messages from every legitimate source instead of assuming a published DNS record proves the complete path.
- Confirm the visible From domain
- Inspect envelope and DKIM signing domains
- Check forwarded and third-party workflows
- Review aggregate reports for unknown sources
Increase enforcement in controlled stages
Remediate legitimate senders, choose an initial scope, monitor results and keep a rollback decision ready. Move toward quarantine or reject only when the business understands remaining failures.