What Is DMARC and How Does It Stop Email Spoofing?

A criminal does not need to break into your mail server to send email from your domain. Email was built open, so anyone on the internet is free to drop your company name into the “From” line. Your customers see a message from you, trust it, and click. This is email spoofing, and it sits behind a large share of the fraud hitting Canadian organizations. The Canadian Anti-Fraud Centre logged more than 112,000 fraud reports and over 704 million dollars in reported losses in 2025. Spear phishing alone drove 67.9 million dollars of those losses, the second-costliest fraud type by dollar amount. DMARC is the control built to shut spoofing down.
DMARC stands for Domain-based Message Authentication, Reporting, and Conformance. It is a record you publish in your domain’s DNS. It tells every receiving mail server what to do with a message claiming to come from you when the message fails authentication. DMARC does not work alone. It sits on top of two older checks, SPF and DKIM, and ties them to the domain your recipients see. The Canadian Centre for Cyber Security states the goal plainly. Only a policy of reject at full enforcement stops every illegitimate message from reaching an inbox.
SPF and DKIM: The Two Checks DMARC Relies On
SPF, the Sender Policy Framework, lists the IP addresses allowed to send mail for your domain. A receiving server checks the sending address against your published list. DKIM, DomainKeys Identified Mail, adds a cryptographic signature to each message. The receiving server verifies the signature against a key in your DNS, which proves the message was not altered in transit. Each check guards one piece. Neither one ties the result to the domain your reader sees in the “From” field. A spoofed message passes SPF or DKIM on a lookalike domain and still lands in the inbox. DMARC closes the gap with alignment.
How Alignment Stops the Spoof
Alignment is the core of DMARC. It forces the domain checked by SPF and DKIM to match the domain shown in the “From” header. An attacker sending from a server they own fails SPF for your domain. They hold no DKIM key for your domain, so the signature check fails too. With alignment required, both failures point at one verdict. The message is not from you. Your DMARC policy then tells the receiving server how to treat it.
The Three Policy Levels
DMARC gives you three settings, applied in order as you gain confidence. You start at p=none. The server delivers everything and sends you reports on what passed and what failed. You read those reports to find every legitimate sender, from payroll tools to marketing platforms to support desks. Next you move to p=quarantine. Failing messages drop into the spam folder instead of the inbox. Last you reach p=reject. The server refuses failing messages outright, so a spoofed email never reaches your staff or your customers. CCCS guidance walks federal departments through the same progression and points reporting at a central address for monitoring.
Why This Matters for Canadian Organizations
Spoofing attacks your brand and your people at the same time. A faked invoice from your finance team. A password reset from your IT desk. A payout request wearing your CEO’s name. Each one trades on the trust your domain carries. Reach p=reject and you remove the easiest version of the attack, because the criminal loses the ability to send as you. Reporting gives you a second win. DMARC aggregate reports show you every service sending mail under your domain, which surfaces shadow IT and misconfigured tools you did not know were running.
Where DMARC Fits in Your Defences
DMARC protects your domain from being forged. It does nothing for a spoof sent from a lookalike domain, a near-match built to fool a rushed reader. It does nothing once a real account is compromised and the attacker sends from inside. You pair DMARC with staff awareness and an incident response plan to cover those gaps. Train your people to question urgency and verify payment changes by phone. Build a response playbook for the report of a spoofed message, so your team reacts the same way every time.
The Skills Behind the Work
Setting a DMARC policy and reading its reports is a security operations task, and the people who do it well understand the attacks they defend against. The Certified Cybersecurity Analyst program covers the monitoring and analysis you need to run DMARC reporting day to day. Email-based attacks also demand a response plan, and the Certified Incident Handling Engineer program teaches the containment steps you follow when a phishing wave hits.
Someone owns the decision to enforce domain protection across every business unit. The Certified Information Systems Security Officer program ties controls like DMARC to risk management and policy. And because spoofing works on people, not servers, the Certified Security Awareness program gives your staff the habits to spot the message DMARC did not block.
Where to Start
Publish a DMARC record at p=none today. Point the reports to a mailbox you check. Give it two to four weeks to show you every sender. Fix your SPF and DKIM records for each legitimate service. Move to quarantine, watch for a month, then move to reject. Align the rollout with CCCS guidance on email domain protection, and keep your reporting on through every stage. The work takes weeks, not months, and the payoff is direct. A criminal loses the easiest way to impersonate your organization, and your customers keep trusting the mail you send.
