DMARC is for life, not just a project

At Red Sift we often get asked “what’s next?” after someone has thrown the p=reject switch. Yes, a lot of the really hard work has been done, but like with all things security-focused, constant care and attention are needed to stay one step ahead of phishers, spoofers, and hackers.

Maintain your existing email sending services

Your DMARC record isn’t a “set it and forget it” solution. Without regular maintenance, issues with SPF or DKIM can arise, potentially causing your legitimate emails to be rejected — often without you realizing it. Here’s why this can happen:

  • Email forwarding: Forwarded emails break SPF authentication.
  • Misalignment: Third-party services can inadvertently misconfigure or desynchronize DKIM keys.
  • Server overload: During peak traffic, some ISPs may temporarily disable DKIM checks due to processing constraints.

Without a tool like Red Sift OnDMARC, identifying and resolving these issues can be a challenge.

This is especially critical when working with third-party email services where you may have limited visibility and control. It’s not uncommon for these providers to stop signing emails with DKIM due to a minor configuration change. Without OnDMARC’s reporting capabilities, you may remain unaware of these changes, making it difficult to rectify issues before they impact your email deliverability.

Add new email services with confidence

DMARC’s continuous reporting not only ensures protection but also helps identify new sources of email traffic — both legitimate and illegitimate. Once a new service appears on your OnDMARC dashboard, you can either configure it correctly with SPF and DKIM or block it if necessary.

A common scenario is when teams like Marketing adopt new tools such as HubSpot or Mailchimp for customer email campaigns without informing IT or email teams. This results in “shadow IT” — unauthorized or unmanaged systems within an organization’s infrastructure.

When DMARC is set to p=reject, emails from these unauthorized services won’t reach recipients, leading to potential disruption. With OnDMARC, however, you can quickly detect these services and work with relevant teams to ensure proper configuration and seamless email delivery.

Futureproof your email architecture

As your organization grows, so does your email ecosystem. Over time, new domains and subdomains will be added — a phenomenon known as domain creep. This often results in more domains under DMARC management than initially anticipated.

Our experience with thousands of DMARC deployments shows that most organizations eventually adopt dedicated domains or subdomains for specific business units, often with tailored policies. Additionally, many purchase parked domains for brand protection, even if no emails are sent from them.

Effectively managing an expanding domain portfolio is essential, especially as your email landscape evolves. What works for your organization today may look very different tomorrow.

To find out more about how OnDMARC helps make DMARC implementation simpler and easier, start your 14 day free trial or get in touch with us below today!

PUBLISHED BY

Red Sift

16 Sep. 2020

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

Over 60% of healthcare organizations remain unprotected against data breaches

Sean Costigan

Introduction Red Sift’s analysis of healthcare organizations that reported large breaches to the Department of Health & Human Services (HHS) in 2023-2024 uncovered a troubling trend: post-breach, 61% remain unprotected against phishing and domain spoofing due to weak or nonexistent DMARC policies. DMARC (Domain-based Message Authentication, Reporting & Conformance) is a widely recognized security…

Read more
Awards

Red Sift wins 2025 Cybersecurity Excellence Award for OnDMARC

Jack Lilley

Executive Summary: Red Sift OnDMARC has been recognized with the 2025 Cybersecurity Excellence Award for its advanced email security solutions. By leveraging AI-powered tools like Red Sift Radar for security issues and Dynamic DNS Guardian for real-time monitoring, OnDMARC provides businesses with robust protection against phishing, spoofing, and business email compromise (BEC).  Key takeaways:…

Read more
Product Release

Red Sift’s Winter ‘24/’25 Quarterly Product Release

Francesca Rünger-Field

This quarter, we’re making security faster, smarter, and more proactive with updates that improve threat detection, reduce manual work, and prevent threats before they escalate. Highlights include: Brand Trust  Executive Impersonation: Detect unauthorized use of leadership identities By uploading and managing executive images in Brand Trust, security teams can detect and monitor unauthorized use…

Read more
AI

Enhanced logo detection with AI: A hybrid approach

Phong Nguyen

Executive Summary: Accurate logo detection is essential for protecting brands against misuse and fraudulent activities. Red Sift’s hybrid AI approach enhances detection precision, effectively balancing the reduction of false positives with the identification of genuine threats. This article: Introduction Logo detection is crucial for brand protection, helping identify logo misuse in lookalike domains and fraudulent…

Read more