Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
IT technicians working at his desk with headphones

30 June 2025

4 minutes read time

What is DMARC, and how does it work?

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Your cybersecurity should be a priority. 

Most modern businesses store their data online, which comes with the risk of a data breach. IT and cybersecurity providers are there to reduce the chances of that happening.

Phishing emails, domain spoofing, and numerous other cyber threats can damage your brand and your relationship with your customers in an instant. 

Read more: Phishing 101: Can you get hacked by opening an email? 

Why is DMARC important?

DMARC is a defence mechanism for your emails. Most businesses nowadays have their own email domain – something along the lines of @companyname.co.uk. 

This provides you with a number of benefits, such as enhanced professionalism. It also builds trust with your customers and reinforces your brand identity. 

Take a look at our full page on Advanced Domain Security

But phishing and spoofing emails can utilise your email domain, pretend to be a member of the company and begin sending spam emails, leaving you open to a data breach or cyber attack. 

This is where DMARC comes in – acting as a bodyguard for your email address. DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a security protocol that helps protect your domain from being used in phishing and spoofing attacks. 

Understanding SPF, DKIM, and DMARC

DMARC uses two protocols: SPF and DKIM. These two elements work together to verify senders and detect tampering or suspicious activity. 

Here’s how they work. 

What is SPF?

SPF (Sender Policy Framework) essentially acts like a bouncer for your email domain. Your domain will have a list of approved IP addresses that indicate you are authorised to send emails on behalf of that domain. 

How it works – a breakdown:

  • You or your IT provider publishes an SPF record in your domain’s settings.
  • This record, as mentioned above, includes a list of approved IP addresses.
  • When someone receives an email from your domain, the server checks the approved list.

This stops spammers from faking your domain.

But what if your email has been tampered with in transit? This is where DKIM comes in.

What is DKIM?

DKIM takes your entire email message (full content and caption) and creates a unique cryptographic hash (a digital fingerprint) which covers your email in a safety net and is stamped with a DKIM header that links to the digital footprint of your DNS. 

This way, emails that have been sent from your domain are checked to make sure that they have not been altered within either the messaging or the links. 

How it works – a breakdown:

  • A pair of cryptographic keys (one public, one private) is generated for the sending domain.
  • The private key that was generated essentially marks the entire mail with a digital fingerprint, including important information such as the sender, recipient, and subject.
  • The other (public) cryptographic key is stored in your server’s DNS records. 
  • So when the receiving email server gets that email, it will retrieve the public key from the server’s DNS records to verify the digital fingerprint on the email.
  • If the signature is valid, it will pass the DKIM authentication.
  • However, the private key is changed and becomes invalid if the email has been tampered with and will therefore fail authentication.

Where does DMARC come in?

DMARC is essentially the enforcer and works with both SPF and DKIM, using the results of both to determine what to do with emails that fail authentication on either or both. 

The beauty of DMARC is that the power is in the hands of the owner of the domain, as flagged emails will come through to them marked as spam or rejected. 

You can keep flagged emails for reporting, allowing you to see where spammers are getting through to improve your email security. 

A final thought

DMARC, DKIM, and SPF are three protocols that are crucial to your business to avoid the likelihood of data breaches and cyber attacks. 

A stat that is echoed continuously is that 95% of data breaches are tied to human error through phishing or spoofing emails. 

Don’t be included in that statistic – utilise these protocols and keep your business safe.

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more