Client Login
Menu

Managed DMARC Services

Anyone can send an email that says it's from your company. Without email authentication, a criminal can put your domain in the "From" line of a fake invoice, a password-reset notice or a wire-transfer request, and your customers and vendors have no easy way to tell it apart from the real thing. At the same time, the big mailbox providers are increasingly sending unauthenticated mail to spam, or refusing it outright, so a domain that isn't set up correctly can also lose legitimate email.

Aspendora Technologies sets up and manages DMARC, SPF and DKIM for businesses in the Houston area and beyond. We find every service that sends email as your domain, fix the authentication for each one, move your domain safely to full enforcement, and keep watching it afterward so a new marketing tool or a changed record doesn't quietly break your email.

Prefer to do it yourself? Our free step-by-step guide to implementing DMARC walks through the whole process, and our email record checker shows where your domain stands today.

DMARC, SPF and DKIM in Plain English

These three standards work together to prove that an email really came from you. Each one is a small text record published in your domain's DNS.

SPF: who is allowed to send

SPF (Sender Policy Framework) is a published list of the mail servers and services allowed to send email for your domain: Microsoft 365 or Google Workspace, your CRM, your billing system, your website's contact form. A receiving server checks whether a message came from a server on that list.

DKIM: a tamper-proof signature

DKIM (DomainKeys Identified Mail) adds a digital signature to each message. The receiving server looks up your public key in DNS and confirms the signature, which proves the message was sent by an authorized system and wasn't altered along the way.

DMARC: the policy that ties them together

DMARC (Domain-based Message Authentication, Reporting and Conformance) checks that SPF or DKIM passed and that it passed for the same domain your recipients see in the "From" line. This matching is called alignment, and it's what stops a spoofer from passing SPF with their own domain while displaying yours. DMARC then does two things:

  • Tells receivers what to do with failures: p=none (monitor only), p=quarantine (send to spam) or p=reject (block).
  • Sends you reports: mailbox providers send daily aggregate reports listing every server that sent mail using your domain and whether it passed. Those reports are how you find senders you didn't know about, and spoofers you'd want to block.

Why DMARC Matters Now

For years DMARC was optional. That has changed:

  • Google and Yahoo: since February 2024, both require bulk senders (Google defines this as sending 5,000 or more messages a day to personal Gmail accounts) to authenticate with SPF and DKIM, publish a DMARC record with at least a p=none policy, and align the "From" domain with SPF or DKIM. Every sender, whatever the volume, is expected to have SPF or DKIM in place.
  • Microsoft: in 2025 Microsoft introduced similar requirements (SPF, DKIM and DMARC) for high-volume senders to its consumer Outlook.com, Hotmail and Live addresses.
  • Spoofing and invoice fraud: business email compromise often relies on email that looks like it comes from someone you trust. A DMARC policy at enforcement makes it much harder for criminals to send mail that uses your exact domain.
  • Questionnaires and audits: cyber insurance applications, vendor security questionnaires and compliance reviews increasingly ask whether you have SPF, DKIM and DMARC in place.

Most small businesses never send 5,000 emails a day, but that doesn't make DMARC optional in practice. Mailbox providers use authentication as a trust signal for everyone, and a domain with no DMARC policy is an open invitation to anyone who wants to impersonate it.

The Problem

Why DMARC projects stall

Unknown Senders

Invoices, newsletters, contact forms and scanners all send as your domain. Miss one, and enforcement blocks your own email.

Unreadable Reports

DMARC reports arrive as compressed XML files every day. Most businesses never open them, so the record sits at p=none forever.

Records Break Quietly

A new marketing tool, a DNS change or too many SPF lookups can break authentication without anyone noticing until email bounces.

How We Implement DMARC, Step by Step

The goal is a domain at p=reject, where spoofed email is blocked, without ever blocking your own legitimate mail on the way there. We get there in stages, and we don't move to the next stage until the reports show it's safe.

1. Discovery: find every service that sends as you

We review your current DNS records and talk with you about the systems your business uses. Your mail platform is the obvious one, but there's usually more: accounting and invoicing software, a CRM or email-marketing service, your website, scanners and copiers, line-of-business applications, and vendors that send on your behalf.

2. Monitor at p=none

We publish (or correct) a DMARC record in monitoring mode and point its reports to our reporting platform. Nothing is blocked yet. For the next few weeks the reports show us every source sending as your domain, how much it sends, and whether it passes, including anything the discovery conversation missed.

3. Fix SPF and DKIM alignment for each sender

Working through the report one sender at a time, we set up DKIM signing with your domain, add legitimate services to SPF, and move bulk or marketing senders to a subdomain where that makes sense. If your SPF record is near the limit of 10 DNS lookups, we manage it as a hosted, flattened SPF record so it stays valid as services are added.

4. Move to quarantine

When legitimate mail is consistently passing, we change the policy to p=quarantine, often applying it to a percentage of failing mail first. Failing messages go to spam instead of the inbox, and we watch the reports for anything legitimate that slipped through.

5. Move to reject

Once quarantine is clean, we move to p=reject. Receiving servers now refuse email that fails DMARC, which is the level of protection that actually stops exact-domain spoofing. We also cover subdomains and any parked domains you own that don't send email, since those are easy targets.

6. Ongoing monitoring and alerting

DMARC isn't set-and-forget. Our reporting platform keeps receiving your reports, and a daily automated check opens a ticket with our team when something changes: a record goes missing or becomes invalid, a legitimate sender starts failing, or a new source appears. We fix it, or tell you what changed and why.

What's Included

  • Sender discovery and DNS review for each domain you own, including subdomains and parked domains.
  • DMARC aggregate report monitoring, collected and turned into readable dashboards instead of raw XML.
  • Hosted DMARC: we manage your DMARC policy for you, so policy changes don't wait on DNS tickets.
  • Hosted SPF management, including SPF flattening to stay under the 10-lookup limit.
  • DKIM setup and alignment for your mail platform and each third-party sender.
  • A staged path to enforcement, from p=none to p=quarantine to p=reject.
  • Daily monitoring that opens tickets when a record breaks, a sender starts failing, or something new appears.
  • Inbound email security filtering for Microsoft 365, available alongside DMARC, which catches phishing and impersonation that doesn't use your exact domain. See our network security services.
The Plan

Getting started is simple

01

Schedule a Discovery Call

Tell us which domains you own and how your business sends email. We’ll check your current records together.

02

We Monitor and Fix

We start reporting at p=none, find every sender, and fix SPF and DKIM alignment one service at a time.

03

Enforce and Relax

We move you to quarantine, then reject, and keep monitoring so your email stays protected and delivered.

Who This Is For

  • Businesses whose email is landing in spam or bouncing, especially invoices, statements and newsletters.
  • Companies that have been spoofed, or whose customers have received fake invoices or payment-change requests "from" them.
  • Anyone stuck at p=none: you published a DMARC record once and never moved it to enforcement.
  • Organizations answering security questionnaires from insurers, customers or auditors, including those working toward HIPAA, PCI or CMMC. See our compliance services.
  • Businesses with several domains or many third-party senders, where keeping SPF valid is a job in itself.
  • In-house IT teams who would rather hand off the reporting and enforcement work. See co-managed IT.

Aspendora Technologies, LLC was founded in 2010, and our founder, Lacy Moore, has worked in IT since 1989. DMARC management is available on its own or as part of our managed IT services.

What You Get

The transformation

  • Spoofed email using your exact domain rejected by receiving servers
  • Every legitimate sender authenticated with aligned SPF or DKIM
  • Email authentication set up to meet the Google, Yahoo and Microsoft sender requirements
  • Readable reports instead of daily XML attachments
  • A daily check that opens a ticket when something breaks
  • A clear answer for insurers, customers and auditors who ask about DMARC
FAQ

Frequently asked questions

What is a managed DMARC service?

Instead of publishing a DMARC record and hoping for the best, we run the whole project for you: we find every service that sends email as your domain, fix SPF and DKIM alignment for each one, move your policy from p=none to p=reject in stages, and keep monitoring the reports afterward, with alerts when something changes.

How long does it take to reach DMARC enforcement?

It depends on how many services send email for you. A small business with only a mail platform can often reach p=reject in a few weeks. Organizations with many third-party senders take longer, because each one has to be identified and fixed and the reports need time to confirm it. We don’t rush enforcement: the pace is set by what the reports show, not by a fixed calendar.

Will DMARC block our legitimate email?

Not if it’s implemented in stages. We start at p=none, which blocks nothing, and only move to quarantine and then reject once the reports show your legitimate senders are passing. Problems usually come from jumping straight to reject before every sender has been found, which is exactly what the monitoring phase prevents.

Is p=none enough to meet the Google and Yahoo requirements?

For the bulk-sender requirement, a DMARC record with at least p=none plus aligned SPF or DKIM is the stated minimum. But p=none doesn’t stop anyone from spoofing your domain; it only reports on it. To actually block spoofed email you need p=quarantine or, ideally, p=reject.

Do small businesses really need DMARC?

Yes. The bulk-sender rules mostly affect high-volume senders, but mailbox providers weigh authentication for everyone, and small businesses are frequent targets of invoice and payment fraud that uses a look-alike or spoofed sender. DMARC at enforcement protects your customers and vendors from fake email in your name, and helps your real email get delivered.

What is SPF flattening, and why would we need it?

SPF allows at most 10 DNS lookups when a receiver evaluates your record. Every service you add with an include: uses some of them, and once you go over the limit SPF fails for all of your mail. Flattening replaces those lookups with the underlying addresses and keeps them up to date automatically. We provide it as a hosted SPF record, so your record stays valid as you add services.

We use Microsoft 365. Isn’t that already set up?

Usually not completely. Microsoft 365 can sign mail with DKIM for your domain, but it has to be turned on and the DNS records published, and Microsoft doesn’t publish a DMARC policy for your domain. It also can’t authenticate the other services that send as you, such as your CRM, invoicing system or website. The same is true of Google Workspace.

Does DMARC stop all phishing?

No. DMARC stops email that uses your exact domain. It doesn’t stop look-alike domains, display-name tricks, or phishing sent from compromised or free accounts. That’s why we pair DMARC with inbound email security filtering, multi-factor authentication and security awareness training as part of our cybersecurity services.

Can you manage DMARC for more than one domain?

Yes. We cover every domain you own, including domains that don’t send email at all. Parked domains should publish a DMARC p=reject policy and an SPF record that allows no senders, so criminals can’t use them either.

How do I check where my domain stands today?

Run your domain through our free email record checker to see your SPF, DKIM and DMARC status, or schedule a free discovery call and we’ll review it with you.

Schedule a Free Discovery Call

Ready to Talk?

Book a free 15-minute discovery meeting. No pressure, no obligation.