Microsoft announces its new handling of DMARC policies

As of March 2023, Microsoft 365 started sending aggregate DMARC reports. This update fixed a blindspot that had existed; previously, where Microsoft didn’t report on DMARC results, you would miss crucial insights and legitimate senders that could then be blocked from sending emails once p=reject was enabled.

Another milestone improvement has now been announced, with Microsoft honoring DMARC policies in M365 and its consumer properties from July 2023.

We have changed our DMARC policy handling to honor the sender’s DMARC policy. If an email fails DMARC validation and the sender’s policy is set to p=reject or p=quarantine, we will reject the email.

Announcing New DMARC Policy Handling Defaults for Enhanced Email Security

Previously, Microsoft did not honor p=reject and would treat the policy in oreject (override reject) mode that behaves like quarantine. This meant that if a sender’s DMARC policy stated “p=reject”, both Outlook.com (including Hotmail and MSN) and Microsoft 365 would put the email in the recipient’s junk folder or spam folder, making it possible for phishing emails to make it into inboxes. Read more about DMARC policies here.

With this update, Microsoft is now honoring and enforcing a domain’s reject policy in M365 and its consumer properties. This means that a domain with a policy of reject will block emails that fail DMARC validation by default. By respecting a domain’s DMARC policy, Microsoft helps create a safe digital environment for its customers and consumers by ensuring that exact domain impersonation attacks are blocked.

Evaluating your DMARC posture is now more important than ever 

With this update, Microsoft joins other top email-sending providers (ESPs) like Yahoo, Gmail, and Apple who all honor DMARC policies. Given this shift in the ESP landscape, it is a good time for companies to evaluate their DMARC posture and make sure they are not inadvertently blocking good emails. 

How Red Sift OnDMARC can help

With Red Sift’s OnDMARC, an award-winning automated DMARC solution, Microsoft 365 customers can enhance their email security and protect against a wide range of outbound and inbound email-based threats. Customers have full visibility of their sending sources, both inbound and outbound, and can expect to reach DMARC enforcement and block malicious spoofing emails from getting to their employees, customers, and partners in as little as 4-8 weeks.

OnDMARC seamlessly plugs into the Microsoft environment and works in harmony with Microsoft Defender for Office 365 to provide a robust layered defense against advanced email threats. The Microsoft Intelligent Security Association (MISA) recognizes and lists OnDMARC as an approved integration and preferred solution in the Azure Marketplace, acknowledging it as fully complementary to Microsoft’s own email security solutions.

“At Microsoft, we look to build enduring, ongoing relationships with partners like Red Sift protecting e-mail and other hybrid work essentials. With increasingly sophisticated cyber criminals targeting email communications, the Red Sift platform helps Microsoft 365 customers to enhance the security of their systems.”

Parri Munsell, Senior Director, Microsoft Security Marketing

Learn more about Red Sift OnDMARC here or if you’d like to jump straight in and get started with a 14-day free trial, just click the link below.


Please note: Microsoft tenant admins also have the ability to customize how they want their tenants to adhere to these DMARC policies. We encourage all Microsoft customers to review their tenant DMARC settings and customize them if needed to benefit from improved email security and deliverability.

PUBLISHED BY

Francesca Rünger-Field

26 Jul. 2023

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Introducing DNS Guardian: Stop impersonation and spam caused by domain takeovers 

Rahul Powar

tl;dr: We’re thrilled to announce DNS Guardian — a new feature in Red Sift OnDMARC that can swiftly identify and stop domain takeovers that lead to malicious mail. Back in February, we shared updates with the community about SubdoMailing – an attack discovered by Guardio Labs. The attack was a form of subdomain takeover,…

Read more
Email

“What’s Next for DMARC”: Red Sift & Inbox Monster Webinar Recap

Red Sift

The recent webinar hosted by Inbox Monster, “What’s Next for DMARC: Data & Predictions for a New Era in Email Authentication,” featured insights from Red Sift and examined the significant changes brought by Yahoo and Google’s bulk sender requirements earlier this year.  It also offered a forward-looking perspective on the future of email authentication.…

Read more
Security

Navigating the Information Security Landscape: ISO 27001 vs. SOC 2

Red Sift

As cyber threats evolve, so do the standards and frameworks designed to combat them. Two of the most recognized standards in information security are ISO 27001 and SOC 2. What sets them apart, and which one is right for your organization? Let’s delve into the key differences. Purpose and Scope: Global Framework vs. Client-Centric…

Read more
News

G2 Summer 2024 Report: Red Sift OnDMARC’s Winning Streak Continues

Francesca Rünger-Field

We’re delighted to announce that Red Sift OnDMARC has again been named a Leader in G2’s DMARC category for Summer 2024. This recognition is based on our high Customer Satisfaction scores and strong market presence. Red Sift appeared in 11 reports – 5 new ones since Spring 2024! – earning 5 badges: A few…

Read more
News

Google will no longer trust Entrust certificates from October 2024

Red Sift

Tl;dr: Google has announced that as of October 31, 2024, Chrome will no longer trust certificates signed by Entrust root certificates. While there is no immediate impact on existing certificates or those issued before 31st October 2024, organizations should start reviewing their estate now. On Thursday 27th June 2024, Google announced that it had…

Read more