DMARC management

Managed DMARC: from reporting to enforcement, without breaking your mail

Anyone can spoof a domain that is not enforcing DMARC. Lion Group takes your domains from no policy — or a permanently stalled p=none — to p=reject, with SPF and DKIM alignment handled for every service that sends mail on your behalf.

How we run a DMARC programme

Four stages, driven by report data rather than guesswork, so enforcement never costs you a legitimate invoice or campaign.

1. Discover

Publish a reporting policy on every domain — including parked and look-alike domains you own — and build the full inventory of who sends mail as you.

2. Align

Fix SPF (with lookup limits in mind) and DKIM signing for each legitimate service, and retire senders nobody owns any more.

3. Enforce

Move from p=none to p=quarantine with a percentage rollout, then to p=reject, verifying report data at each step so nothing legitimate is lost.

4. Sustain

Ongoing monitoring, alerting on new senders and failures, plus BIMI, MTA-STS and TLS-RPT once enforcement holds.

What the service includes

  • DMARC, SPF and DKIM record design and change guidance for your DNS team
  • Aggregate (RUA) report parsing with per-sender pass and fail trends
  • Spoofing and abuse detection on your primary and parked domains
  • Sender inventory covering marketing, billing, HR and third-party mailers
  • Staged enforcement plan with rollback criteria at every step
  • Executive and auditor-ready reporting on authentication posture
  • BIMI, MTA-STS and TLS-RPT rollout once p=quarantine or p=reject is stable

Service tiers

DMARC Core

Monitoring and reporting for a small domain estate: policy publication, aggregate report analysis and a prioritised alignment backlog.

DMARC Pro

Everything in Core plus hands-on SPF and DKIM remediation across sending services, forensic insight and a managed path to enforcement.

DMARC Enterprise

Multi-domain, multi-business-unit programmes: subsidiary and parked-domain coverage, BIMI and MTA-STS rollout, and reporting for auditors and insurers.

Get DMARC pricing

DMARC FAQ

What is DMARC management?

DMARC management is the ongoing work of publishing a DMARC policy for your domains, collecting and reading the aggregate (RUA) reports that receivers send back, fixing SPF and DKIM alignment for every legitimate sending service, and then tightening the policy from p=none to p=quarantine and finally p=reject. It is a continuous process, not a one-off DNS record, because sending services change constantly.

Why is p=none not enough?

A DMARC record with p=none only asks for reports; it instructs receivers to deliver spoofed mail anyway. Only p=quarantine and p=reject actually stop someone sending mail that appears to come from your domain. Most domains that were 'DMARC compliant' during an incident were sitting at p=none.

Will DMARC enforcement break our legitimate email?

It can, if enforcement is switched on before every sending source is authenticated — marketing platforms, CRMs, ERP and invoicing systems, ticketing tools, HR and payroll services, and third parties that mail on your behalf. We work through the report data source by source, align each one with SPF and DKIM, and only then raise the policy in controlled steps.

How long does it take to reach p=reject?

For a typical organisation with a handful of sending services, four to eight weeks. Larger estates with many domains, business units and third-party senders usually take a quarter. The first two weeks are pure visibility: publish the record, gather reports, discover senders nobody documented.

What are BIMI, MTA-STS and TLS-RPT?

They are the layers you can add once DMARC is enforced. BIMI shows your verified logo next to your mail in supporting inboxes, MTA-STS forces TLS on inbound connections, and TLS-RPT reports on delivery encryption failures. BIMI in particular requires p=quarantine or p=reject, so DMARC enforcement is the prerequisite.

How is DMARC different from anti-phishing?

DMARC protects your outbound identity: it stops attackers spoofing your exact domain to your customers, partners and staff. Anti-phishing protects your people from mail arriving from anywhere else — look-alike domains, compromised suppliers and BEC. You need both; we deliver both.