Anyone can send an email that says it's from your company. Without email authentication, a criminal can put your domain in the "From" line of a fake invoice, a password-reset notice or a wire-transfer request, and your customers and vendors have no easy way to tell it apart from the real thing. At the same time, the big mailbox providers are increasingly sending unauthenticated mail to spam, or refusing it outright, so a domain that isn't set up correctly can also lose legitimate email.
Aspendora Technologies sets up and manages DMARC, SPF and DKIM for businesses in the Houston area and beyond. We find every service that sends email as your domain, fix the authentication for each one, move your domain safely to full enforcement, and keep watching it afterward so a new marketing tool or a changed record doesn't quietly break your email.
Prefer to do it yourself? Our free step-by-step guide to implementing DMARC walks through the whole process, and our email record checker shows where your domain stands today.
These three standards work together to prove that an email really came from you. Each one is a small text record published in your domain's DNS.
SPF (Sender Policy Framework) is a published list of the mail servers and services allowed to send email for your domain: Microsoft 365 or Google Workspace, your CRM, your billing system, your website's contact form. A receiving server checks whether a message came from a server on that list.
DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving server looks up your public key in DNS and confirms the signature, which proves the message was sent by an authorized system and wasn't altered along the way.
DMARC (Domain-based Message Authentication, Reporting and Conformance) checks that SPF or DKIM passed and that it passed for the same domain your recipients see in the "From" line. This matching is called alignment, and it's what stops a spoofer from passing SPF with their own domain while displaying yours. DMARC then does two things:
p=none (monitor only), p=quarantine (send to spam) or p=reject (block).For years DMARC was optional. That has changed:
p=none policy, and align the "From" domain with SPF or DKIM. Every sender, whatever the volume, is expected to have SPF or DKIM in place.Most small businesses never send 5,000 emails a day, but that doesn't make DMARC optional in practice. Mailbox providers use authentication as a trust signal for everyone, and a domain with no DMARC policy is an open invitation to anyone who wants to impersonate it.
Invoices, newsletters, contact forms and scanners all send as your domain. Miss one, and enforcement blocks your own email.
DMARC reports arrive as compressed XML files every day. Most businesses never open them, so the record sits at p=none forever.
A new marketing tool, a DNS change or too many SPF lookups can break authentication without anyone noticing until email bounces.
The goal is a domain at p=reject, where spoofed email is blocked, without ever blocking your own legitimate mail on the way there. We get there in stages, and we don't move to the next stage until the reports show it's safe.
We review your current DNS records and talk with you about the systems your business uses. Your mail platform is the obvious one, but there's usually more: accounting and invoicing software, a CRM or email-marketing service, your website, scanners and copiers, line-of-business applications, and vendors that send on your behalf.
We publish (or correct) a DMARC record in monitoring mode and point its reports to our reporting platform. Nothing is blocked yet. For the next few weeks the reports show us every source sending as your domain, how much it sends, and whether it passes, including anything the discovery conversation missed.
Working through the report one sender at a time, we set up DKIM signing with your domain, add legitimate services to SPF, and move bulk or marketing senders to a subdomain where that makes sense. If your SPF record is near the limit of 10 DNS lookups, we manage it as a hosted, flattened SPF record so it stays valid as services are added.
When legitimate mail is consistently passing, we change the policy to p=quarantine, often applying it to a percentage of failing mail first. Failing messages go to spam instead of the inbox, and we watch the reports for anything legitimate that slipped through.
Once quarantine is clean, we move to p=reject. Receiving servers now refuse email that fails DMARC, which is the level of protection that actually stops exact-domain spoofing. We also cover subdomains and any parked domains you own that don't send email, since those are easy targets.
DMARC isn't set-and-forget. Our reporting platform keeps receiving your reports, and a daily automated check opens a ticket with our team when something changes: a record goes missing or becomes invalid, a legitimate sender starts failing, or a new source appears. We fix it, or tell you what changed and why.
p=none to p=quarantine to p=reject.Tell us which domains you own and how your business sends email. We’ll check your current records together.
We start reporting at p=none, find every sender, and fix SPF and DKIM alignment one service at a time.
We move you to quarantine, then reject, and keep monitoring so your email stays protected and delivered.
Aspendora Technologies, LLC was founded in 2010, and our founder, Lacy Moore, has worked in IT since 1989. DMARC management is available on its own or as part of our managed IT services.
Instead of publishing a DMARC record and hoping for the best, we run the whole project for you: we find every service that sends email as your domain, fix SPF and DKIM alignment for each one, move your policy from p=none to p=reject in stages, and keep monitoring the reports afterward, with alerts when something changes.
It depends on how many services send email for you. A small business with only a mail platform can often reach p=reject in a few weeks. Organizations with many third-party senders take longer, because each one has to be identified and fixed and the reports need time to confirm it. We don’t rush enforcement: the pace is set by what the reports show, not by a fixed calendar.
Not if it’s implemented in stages. We start at p=none, which blocks nothing, and only move to quarantine and then reject once the reports show your legitimate senders are passing. Problems usually come from jumping straight to reject before every sender has been found, which is exactly what the monitoring phase prevents.
For the bulk-sender requirement, a DMARC record with at least p=none plus aligned SPF or DKIM is the stated minimum. But p=none doesn’t stop anyone from spoofing your domain; it only reports on it. To actually block spoofed email you need p=quarantine or, ideally, p=reject.
Yes. The bulk-sender rules mostly affect high-volume senders, but mailbox providers weigh authentication for everyone, and small businesses are frequent targets of invoice and payment fraud that uses a look-alike or spoofed sender. DMARC at enforcement protects your customers and vendors from fake email in your name, and helps your real email get delivered.
SPF allows at most 10 DNS lookups when a receiver evaluates your record. Every service you add with an include: uses some of them, and once you go over the limit SPF fails for all of your mail. Flattening replaces those lookups with the underlying addresses and keeps them up to date automatically. We provide it as a hosted SPF record, so your record stays valid as you add services.
Usually not completely. Microsoft 365 can sign mail with DKIM for your domain, but it has to be turned on and the DNS records published, and Microsoft doesn’t publish a DMARC policy for your domain. It also can’t authenticate the other services that send as you, such as your CRM, invoicing system or website. The same is true of Google Workspace.
No. DMARC stops email that uses your exact domain. It doesn’t stop look-alike domains, display-name tricks, or phishing sent from compromised or free accounts. That’s why we pair DMARC with inbound email security filtering, multi-factor authentication and security awareness training as part of our cybersecurity services.
Yes. We cover every domain you own, including domains that don’t send email at all. Parked domains should publish a DMARC p=reject policy and an SPF record that allows no senders, so criminals can’t use them either.
Run your domain through our free email record checker to see your SPF, DKIM and DMARC status, or schedule a free discovery call and we’ll review it with you.
Book a free 15-minute discovery meeting. No pressure, no obligation.
We ask before we track you.
Nothing from Google, Microsoft, or Meta loads on this site unless you say yes. We keep basic, cookieless visit counts on our own server either way. Details in our Privacy Policy.
Essential site function and first-party, cookieless visit counts run either way and can't be switched off here.