Enterprise-wide DMARC Deployment Checklist
An enterprise-wide DMARC deployment checklist is not “publish one TXT record on the website domain.” It is a programme: every brand name you own, every platform that sends as those names, a policy path you can defend to security and finance, and a cadence so the work does not stall on p=none.
This is a DMARC rollout strategy for global enterprise estates and for smaller South African groups with more than one legal entity. It is not a quote for SLA-backed support. Use it as the operating sequence. For the first DNS record on a single zone, start with how to set up DMARC. For one domain already monitoring, use the path from p=none to p=reject.
What “enterprise-wide” actually means
A single apex record does not cover:
- regional and product brands on other zones
- parked or campaign names still in the registrar account
- subdomains that send mail under a different identity
- SaaS tools marketing connected last quarter
Receivers evaluate the From domain on each message. Your programme has to follow that, not the org chart.
The checklist (in order)
Do not skip ahead to p=reject to satisfy an audit slide. The order is the risk control.
1. Inventory domains before you touch DNS
Finish a list you can walk in one workshop:
- registrar logins (every account, not only the “main” one)
- DNS hosts and certificate inventory
- legal entity / trademark names
- M&A leftovers
- marketing campaign domains from the last few years
Classify each name: active corporate, active sending, parked / brand only, redirect only, decommission. Parked names need a no-send posture — see unused domains and email authentication.
2. Name owners
For each active domain:
- who may edit DNS
- who owns the mailbox platforms (Microsoft 365 / Google Workspace)
- who owns marketing / billing / support senders
- who reads aggregate reports every week
If “IT will do DMARC” has no named human for reports, you will archive XML and call it monitoring.
3. Publish monitoring you will actually read
On each in-scope sending domain, publish DMARC at p=none with a rua address that lands in a mailbox or tool someone opens. Confirm the record with a free domain check.
Then learn the four triage questions in how to read DMARC aggregate reports. Unread rua is archiving, not a deployment.
4. Map senders before you add more SPF includes
From two to four weeks of reports (longer if volume is bursty):
- list every high-volume source
- mark known vs unknown
- note whether SPF and DKIM passed and whether they aligned to the visible From
New tools get the SaaS sender onboarding checklist before they send. Do not paste another include: onto a record already near the 10-lookup limit — that is how you get an SPF permerror.
5. Fix alignment, not dashboard ticks
SPF pass and DKIM pass are not a DMARC pass. Alignment is the missing column: the authenticated domain must prove the brand the recipient sees. Read DMARC alignment explained.
Operational preference for bulk and transactional mail: brand-domain DKIM on each live From, then confirm on a real message header — not only a vendor admin tick.
6. Raise policy in stages, per domain
When known senders pass consistently:
p=none→p=quarantine(watch support and finance mail)- hold
p=quarantine→p=reject- keep a rollback record ready
p=none is a phase. Staying there forever is not protection. Walk the enforcement path on the primary brand first if you need a single-domain rehearsal.
Do not flip every domain to reject on the same Friday.
7. Subdomains and organisational policy
Decide sp= (subdomain policy) deliberately. Marketing subdomains often should not inherit a sudden reject from apex until those streams are inventoried. Strict alignment (adkim=s / aspf=s) is a precision tool after the estate is clean — not a first-week “security win.”
8. What DMARC will not do
Budget process time alongside DNS:
- lookalike domain names are not stopped by DMARC on your real zone
- mailbox compromise still sends authenticated mail
- BEC still needs payment controls
Say this out loud to finance. Otherwise the programme gets blamed for the attack it was never designed to stop.
9. Cadence after the first reject
Quarterly at minimum:
- re-run domain inventory
- review new SaaS
- confirm parked names still have a no-send posture
- check bulk-sender rules if you send marketing volume (Gmail/Yahoo, Microsoft Outlook)
A one-page status update for leadership
Replace “we have DMARC” with:
| Field | Example |
|---|---|
| Domains in inventory | N names, N classified |
| Policy on primary brand | p=quarantine since date |
| Known aligned volume | ~X% of reported volume |
| Next policy step | domain + date |
| Residual (not DNS) | lookalikes, mailbox process |
That is an enterprise-wide status. A TXT screenshot is not.
Where this sits relative to self-serve
Single-domain teams can run the same sequence with setup guides and a free check. Multi-brand programmes that need a quoted conversation can start at For Teams or Enterprise. We do not claim SLA-backed support in this article; any SLA is only what is agreed in writing.
Final takeaway
Enterprise DMARC is a rollout, not a record. Inventory, readable reports, aligned senders, staged policy, and honest residual risk. Publish monitoring this week if you have not; do not call the programme done until the primary brand can defend a path off p=none.