DMARC Email Trust Baseline (SPF / DKIM / DMARC)

A plain-English checklist and rollout outline to improve email trust, reduce spoofing, and make domain protection easier to manage for NZ SMEs.

Security Email Trust DMARC SPF DKIM
What this solves
Email spoofing, weak domain trust, finance/payment fraud exposure, and uncertainty around whether your email domain is protected properly.

1) Fast checks (do first)

CheckWhat good looks likeStatus / notes
SPF publishedYour domain publishes one valid SPF record and it includes only the senders you actually use.
DKIM enabledOutbound mail is signed for your main business platform(s).
DMARC record publishedA valid DMARC policy exists, even if it begins at monitor/report-only stage.
Mail providers understoodYou know all platforms sending mail as your domain.
Reporting owner setDMARC reports have a monitored mailbox or service owner.

2) Recommended rollout path

  1. Inventory senders: list every platform that sends email as your domain.
  2. Publish / verify SPF: remove obsolete senders and keep the record tidy.
  3. Enable DKIM: switch signing on for Microsoft 365 and any other major platforms.
  4. Publish DMARC in monitor mode: start with p=none and collect reports.
  5. Review failures: identify legitimate senders that are not aligned and fix them.
  6. Tighten policy: move gradually from monitor to quarantine/reject when evidence supports it.

3) Questions to ask your IT person / MSP

QuestionWhy it matters
What systems send mail as our domain?Miss one and DMARC rollout becomes noisy or breaks legitimate mail.
Are SPF and DKIM aligned for Microsoft 365 and website forms?Alignment is what makes DMARC meaningful.
Who is reviewing DMARC reports?Reports are only useful if someone owns them.
What is our target policy and by when?You need a path from monitoring to stronger protection.

4) Minimum baseline outcome

5) Common gotchas

Note: This document is general operational guidance and does not replace legal advice. It helps you establish a practical baseline and reduce common privacy risks.
👉 Free 30-minute consultation

No hard sell - just clarity and practical next steps.

hello@virtusgroup.biz
virtusgroup.co.nz
0800 847 887 (VIRTUS)

Book now