An Office 365 reporting module for DMARC

Update

This module will no longer be required as of March 2023 as Microsoft is rolling out DMARC aggregate reports for all Exchange Online Protection customers.

As Microsoft Office 365 will send DMARC reports, the module will be unnecessary. It previously covered a blind spot created by lack of reporting on Microsoft’s part.

Microsoft’s Office 365 Roadmap features the DMARC reporting here.

!!! Read above !!!

DMARC (Domain-based Message Authentication, Reporting and Conformance) is considered the industry standard for email authentication to prevent phishing attacks. As proud members of Microsoft’s Intelligent Security Association (MISA) we’ve worked to create a unique O365 reporting module for Microsoft customers using OnDMARC. Without this module, crucial DMARC reports would not be available which could mean legitimate emails being blocked when moving to a DMARC policy of full protection (p=reject).

How does this happen?

When you invest in a solution like OnDMARC you put a DMARC record in your DNS to be able to view reports sent back from all receiving inboxes. At the moment Microsoft doesn’t currently report on DMARC, which means you could miss crucial insight (and legitimate senders) that could then be blocked from sending emails once you flick the switch to p=reject.

Even if you are already at p=reject, any new services added in the future that report DMARC via O365 may also be missed and blocked without this module.

How will the O365 reporting module resolve this issue?

At Red Sift we pride ourselves on OnDMARC’s full visibility and clear and easy guidance to configure DMARC for your email. This is why we developed a specific solution for the visibility of O365 reports. To sum up, this module adds value if:

• You are working on, or have achieved full DMARC compliance
• You use Microsoft Office 365
• You do not have a third party Secure Email Gateway in front of O365

How does it work?

Office 356 can be configured with our fully supported scripts
to send daily aggregate DMARC reports (in CSV form) to OnDMARC. This data is then surfaced in the Reports section of OnDMARC via a special O365 tab.

One of the things your O365 reporting module will allow you
to do is flag sources seen via O365 that have not already
been seen in your standard DMARC reports. This fixes the blind spot that would have otherwise been there. Without this module you can move to reject and create service disruptions because legitimate O365 senders may be missed.

Attack intelligence along the road to reject

If someone were to launch a highly targeted attack specifically at your employees before you are at policy of p=reject then this too
will not appear in a regular DMARC report and is, therefore, left undetected. Once in reject, these malicious attacks are blocked by OnDMARC, but you would be missing useful intelligence on who attacked your domain without the O365 reporting module. It’s good practice to have full visibility of such targeted attacks as it can be a useful indicator of the threat level the business is experiencing.

How easy is it to set up the O365 module?

We simply provide access to our unique O365 module inside your OnDMARC dashboard which instantly gives you the ability to access the extra reporting functionality for O365. As a fully supported add-on, we will ensure that a member of our support team guides you through the implementation which requires running a few simple PowerShell scripts on your O365 instance.

It is important to note that although Microsoft says they plan to re-enable DMARC reporting in the future they have not yet given a date for this. We fully support our O365 user base and as proud MISA members (Microsoft’s Intelligent Security Association) we have put this crucial module in place to ensure that those invested in DMARC compliance have a straightforward path to reject.

Get in touch today to find out how you can use OnDMARC’s O365 reporting module to uncover blind spots for accurate DMARC compliance.

PUBLISHED BY

Red Sift

9 Sep. 2020

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
News

Introducing DNS Guardian: Stop impersonation and spam caused by domain takeovers 

Rahul Powar

tl;dr: We’re thrilled to announce DNS Guardian — a new feature in Red Sift OnDMARC that can swiftly identify and stop domain takeovers that lead to malicious mail. Back in February, we shared updates with the community about SubdoMailing – an attack discovered by Guardio Labs. The attack was a form of subdomain takeover,…

Read more
Email

“What’s Next for DMARC”: Red Sift & Inbox Monster Webinar Recap

Red Sift

The recent webinar hosted by Inbox Monster, “What’s Next for DMARC: Data & Predictions for a New Era in Email Authentication,” featured insights from Red Sift and examined the significant changes brought by Yahoo and Google’s bulk sender requirements earlier this year.  It also offered a forward-looking perspective on the future of email authentication.…

Read more
Security

Navigating the Information Security Landscape: ISO 27001 vs. SOC 2

Red Sift

As cyber threats evolve, so do the standards and frameworks designed to combat them. Two of the most recognized standards in information security are ISO 27001 and SOC 2. What sets them apart, and which one is right for your organization? Let’s delve into the key differences. Purpose and Scope: Global Framework vs. Client-Centric…

Read more
News

G2 Summer 2024 Report: Red Sift OnDMARC’s Winning Streak Continues

Francesca Rünger-Field

We’re delighted to announce that Red Sift OnDMARC has again been named a Leader in G2’s DMARC category for Summer 2024. This recognition is based on our high Customer Satisfaction scores and strong market presence. Red Sift appeared in 11 reports – 5 new ones since Spring 2024! – earning 5 badges: A few…

Read more
News

Google will no longer trust Entrust certificates from October 2024

Red Sift

Tl;dr: Google has announced that as of October 31, 2024, Chrome will no longer trust certificates signed by Entrust root certificates. While there is no immediate impact on existing certificates or those issued before 31st October 2024, organizations should start reviewing their estate now. On Thursday 27th June 2024, Google announced that it had…

Read more