Yes, unless your domain tells receiving mail servers how to check. SPF lists the servers allowed to send your email, DKIM signs it, and DMARC tells receivers what to do when a message fails those checks. With DMARC set to reject, most mail services will refuse email that falsely uses your exact domain.
Reviewed by Ben Webster
Email was designed without a way to prove who sent a message. Anyone can put your address in the From line, the same way anyone can write your return address on an envelope. Three records you publish in your domain's DNS let receiving mail servers check.
ASD recommends all three. SPF and DKIM on their own don't tell a receiver what to do with a failing message. DMARC does.
The p= setting in your DMARC record is the instruction to receivers:
The usual path is to start at p=none, use the reports to find every service that legitimately
sends your email, fix their SPF and DKIM, then move to quarantine and finally reject.
DMARC protects your exact domain. It doesn't stop a scammer registering a lookalike domain, or sending from a real mailbox they have broken into. That is how many payment redirection scams work: ASD's alert on property-related business email compromise describes criminals posing as real estate agents and conveyancers to change bank details for settlement and rent. Multi-factor authentication on email, and confirming any change to payment details by phone on a number you already have, cover what DMARC doesn't.
To see how your domain is set up today, run a free CertIQ check. Our guide What is DMARC? goes further.
It is DMARC's monitoring mode. Receivers check your email and can send you reports, but they deliver failing messages as normal. It is a sensible first step while you confirm every legitimate sender is set up, but it doesn't stop anyone sending as you.
With p=quarantine, receivers treat failing messages as suspicious, usually sending them to spam. With p=reject, they refuse them. Reject is the strongest setting, and the goal once your reports show legitimate email passing.
No. It stops others using your exact domain in the From address at mail services that check DMARC. It doesn't stop lookalike domains, such as one letter changed, or a scammer using a genuine account they have broken into. Multi-factor authentication on email accounts and confirming payment changes by phone still matter.
A free CertIQ check looks up your SPF, DMARC and common DKIM records and tells you what each is set to, in plain English.
General information only, not financial or insurance advice. Talk to a licensed broker about your situation.
Enter your website and CertIQ scores your cyber health out of 100 in under 10 seconds, with a short Essential Eight self-assessment. Free, no account needed.
More answers: What is the Essential Eight? · Do I need cyber insurance? · How much does cyber insurance cost in Australia? · A customer sent me a cyber security questionnaire. Where do I start?