Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Cyber Security

DMARC Setup Service for SPF, DKIM and DMARC Enforcement

We find every service that sends mail as your domain, publish correct SPF, DKIM and DMARC records, and move you to enforcement without blocking your own email.

Veteran-LedSDVOSB
Standards-BasedCurrent IETF RFCs
Written PlanEvery Domain
Arizona-BasedCasa Grande
NationwideRemote Delivery

When you need a DMARC setup service

A DMARC setup service gets your domain’s email authentication right. SPF lists the servers allowed to send as your domain, DKIM signs each message so receivers can check it was not altered, and DMARC tells Gmail, Yahoo, Outlook.com and corporate mail filters what to do when a message that claims to be from you fails those checks. Honeybadger Solutions delivers this work as part of our managed cyber security services, next to our Microsoft 365 and SaaS security work.

Most businesses set up SPF once, years ago, and never looked again. Since then they added a CRM, a billing platform, a help desk, a payroll provider and a marketing tool, each sending mail as the company domain. Some of that mail now fails authentication, and anyone can still forge the domain because DMARC was never moved past monitoring.

You likely need help if any of these sound familiar:

  • Invoices, statements or password resets land in spam or bounce.
  • Bounce messages mention Gmail error 5.7.26 or the Outlook.com error 550 5.7.515.
  • Customers or vendors received fake invoices that appeared to come from your domain.
  • A cyber insurance or vendor security questionnaire asks whether DMARC is enforced.
  • Your SPF record has grown long, or you are not sure who added which entry.
  • You own extra domains, such as old brand names, that nobody monitors.

What changed for bulk senders in 2024 and 2025?

The large mailbox providers turned email authentication from a best practice into a delivery requirement. Here is what each one published, as of October 2026:

Provider Who it covers What is required Start date
Google (Gmail) All senders; stricter rules above 5,000 messages a day to Gmail accounts All senders: SPF or DKIM. Bulk senders: SPF and DKIM, a DMARC record (policy may be none), From: domain aligned with SPF or DKIM, one-click unsubscribe for marketing mail, spam rate kept below 0.30% February 1, 2024
Yahoo All senders; stricter rules for bulk senders All senders: SPF or DKIM. Bulk senders: SPF and DKIM, a DMARC policy of at least p=none that passes, one-click unsubscribe, unsubscribes honored within 2 days Enforcement began February 2024
Microsoft Outlook.com (outlook.com, hotmail.com, live.com) Domains sending more than 5,000 emails a day SPF pass, DKIM pass, DMARC of at least p=none aligned with SPF or DKIM (preferably both); failing mail rejected with 550 5.7.515 May 5, 2025

Below those volume thresholds the rules still matter. Google requires SPF or DKIM from every sender, and DMARC is the only one of the three that lets you tell receivers to refuse forged mail that uses your exact domain.

Did the DMARC standard change in 2026?

Yes. In May 2026 the IETF published DMARC as a Standards Track specification, RFC 9989, with companion RFC 9990 for aggregate reports and RFC 9991 for failure reports. Together they replace RFC 7489 from 2015. The practical changes: the pct tag that many guides still recommend for a gradual rollout was removed, a new t tag signals test mode, and a new np tag sets policy for subdomains that do not exist.

RFC 9989 also gives direct advice on enforcement. Domains that publish p=reject must sign their mail with DKIM rather than rely on SPF alone, because forwarding breaks SPF while DKIM signatures usually survive. Domains whose users post to mailing lists should not publish p=reject, and any domain moving to reject should first run p=none for at least a month and then p=quarantine for an equally long period. We build every enforcement plan on that current text.

What we deliver

Four services cover email authentication from first record to ongoing care. You can buy the setup alone or pair it with monthly monitoring.

DMARC, SPF and DKIM setup

Priced per domain with a capped block of engineer time. We inventory every service that sends as the domain, write a single SPF record that stays within the lookup limit, turn on DKIM signing for each platform, publish DMARC with reporting, and give you a written enforcement plan. Changes inside third-party platforms depend on what each vendor supports.

DMARC monitoring and administration

A monthly service per domain. We collect and read the aggregate reports, flag new or failing senders, and use a small monthly allowance of admin time per domain for record updates and policy steps from none to quarantine to reject. Larger projects are quoted separately.

Email security management

Per mailbox, per month. Includes the inbound filtering license and routine quarantine administration: releasing legitimate mail, blocking repeat senders and tuning rules. It catches the phishing that DMARC cannot, such as lookalike domains and compromised vendor accounts.

Microsoft 365 or Google Workspace administration

Per user, per month. User and group administration and standard tenant settings, including the DKIM keys and mail flow settings that authentication depends on. This is already included in our managed service packages.

How a DMARC setup service engagement runs

  1. Request online. List every domain you own, including parked and old brand domains, and tell us which mail platform you use.
  2. Read-only review. We check your current MX, SPF, DKIM and DMARC records, count SPF lookups against the limit of 10 set by RFC 7208, and note any duplicate or broken records.
  3. Sender inventory. A short interview plus DMARC reporting at p=none shows every system sending as your domain: CRM, billing, marketing, help desk, payroll, scanners and web forms.
  4. Configure. We publish one clean SPF record, enable DKIM for each platform, and publish DMARC with an address for aggregate reports. Domains that never send mail get records that authorize no senders and reject forgeries.
  5. Watch and fix. For several weeks we read the reports and fix each legitimate sender that fails alignment.
  6. Move to enforcement. We step the policy to quarantine and then to reject where that is safe for your users, following the RFC 9989 timing guidance.
  7. Hand off or monitor. You receive a record-by-record summary. With monitoring, we keep reading reports every month so new vendors do not break delivery.

Authority, consent and legal limits

We change DNS records and mail settings only for domains and tenants you own or are authorized to administer, and only after written approval from the account owner. We work through delegated admin roles you grant, not shared passwords, and every change is logged.

We do not send spoofed test mail to other organizations, probe other companies’ mail servers, or take action against lookalike domains registered by someone else. If we find a lookalike domain, we document it so your counsel can decide on a registrar complaint or legal step. If a forged invoice has already led to a payment, treat it as an incident: use our business email compromise investigation service and report the fraud to the FBI’s IC3.

For context, CISA’s Binding Operational Directive 18-01, issued October 16, 2017, required federal executive branch agencies to reach a DMARC policy of reject on their domains within one year. It does not bind private businesses, but it shows the standard most security reviewers expect. This is general information, not legal advice.

How it is priced

Our DMARC setup service is priced in words here and in numbers on your written quote. Setup is a fixed package per domain with a stated block of engineer hours; a domain with an unusual number of senders is scoped before we start, and extra work is added only by written change order. Monitoring is a monthly fee per domain, with a monthly minimum per customer, and includes reporting plus a small admin allowance per domain. Email security is billed per mailbox per month with a customer minimum. Tenant administration is billed per user per month with a minimum per tenant, or included in a managed services package.

The main cost drivers are the number of domains, the number of third-party platforms sending as you, and whether those platforms support custom DKIM keys.

Included Quoted separately
Sender inventory, SPF, DKIM and DMARC records for the domain in scope Additional domains and subdomains that send their own mail
Written enforcement plan and record summary Mail migrations or tenant moves
Monthly report review and policy steps (with monitoring) Work beyond the monthly admin allowance
Routine quarantine administration (with email security) Investigation of a spoofing or wire fraud incident

Mistakes to avoid with SPF, DKIM and DMARC

  • Publishing two SPF records. RFC 7208 says a domain must not have more than one; receivers treat it as a permanent error.
  • Going past 10 lookups. Every include adds DNS lookups. Past the limit of 10, SPF fails for all of your mail, not only the newest vendor.
  • Jumping straight to p=reject. Without weeks of reports you will block your own payroll notices or invoices.
  • Relying on SPF alone. Forwarded mail usually fails SPF. DKIM is what keeps legitimate forwarded mail passing.
  • Forgetting parked domains. Domains that never send mail are easy to forge unless they publish records that say so.
  • Never reading the reports. A DMARC record with no one reviewing reports tells you nothing about new failures or spoofing.

Before you request service, gather your domain registrar and DNS host logins (you keep them; we request delegated access), a list of tools that email customers, and any recent bounce messages.

Who this is for

  • Businesses that email invoices and statements
  • Marketing teams using bulk email platforms
  • Law firms and accounting firms
  • Medical and dental practices
  • Nonprofits sending donor mail
  • Companies hit by spoofing or fake invoices

Why the online request is faster

When you pick DMARC and email authentication on the online request form, it goes straight to the cyber and forensics lead who handles this work. You list your domains once, we review your public DNS records before the first conversation, and there is no phone tag.

Frequently asked questions

How long does DMARC setup take?

Records publish within minutes, but reaching enforcement safely takes weeks. RFC 9989 suggests at least a month at p=none and an equal period at quarantine for domains whose users post to mailing lists. Domains with few senders can often move faster.

Do I need DMARC if I send fewer than 5,000 emails a day?

Yes, in most cases. Google requires SPF or DKIM from every sender, and only DMARC lets you tell receivers to reject forged mail using your exact domain. The 5,000-message thresholds add stricter rules; they are not the only reason to deploy it.

Will DMARC stop all phishing that uses our name?

No. DMARC stops exact-domain spoofing at receivers that check it. It does not stop lookalike domains or a real mailbox that has been taken over. That is why we pair it with filtering, multifactor authentication and staff training.

What is a DMARC aggregate report?

Receivers send daily XML reports, now defined in RFC 9990, to the address in your DMARC record. They list which servers sent mail as your domain and whether each message passed. Our monitoring turns them into a short monthly summary.

Does a DMARC setup service work with Microsoft 365 and Google Workspace?

Yes. Both platforms support DKIM signing with your own domain. We configure it inside your tenant through an admin role you grant, then do the same for each outside platform that sends as you.

Someone already spoofed us and a customer paid a fake invoice. Can you help?

Yes, but treat it as an incident first. Use our urgent intake form, preserve the messages and headers, contact your bank, and report to IC3. We investigate the compromise and then fix authentication so it is harder to repeat.

Related guides

We change DNS and mail settings only for domains and tenants you own or are authorized to administer, with written approval from the account owner.

Sources: Google email sender guidelines, Yahoo sender best practices, Outlook.com high-volume sender requirements, RFC 7208 (SPF), RFC 6376 (DKIM), RFC 9989 (DMARC).

Stop forged mail without blocking your own

Request this service online, list your domains, and our cyber lead will review your public records before we talk. Picking the service on the form routes it straight to the right specialist, so there is no phone tag. If a spoofed message has already led to a payment or a breach, use our urgent intake form instead.