Inventory actual senders
List corporate mail servers, campaign platforms, CRM, portals, accounting systems, support services and devices that send notifications. For each source, record an owner, the visible From domain, return path, DKIM signature and expected volume.
Look specifically for shadow senders: old website forms, printers, test services and contractors. They are often discovered only after policy enforcement begins.
Verify alignment, not separate check marks
DMARC uses SPF and DKIM but requires an authenticated identifier to align with the author's domain. Passing SPF for a provider's technical domain does not authenticate a branded From address, and a valid signature under an unrelated domain does not produce a DMARC pass.
Use a controlled DKIM domain, key rotation and a fallback path for critical flows. Keep SPF maintainable and within DNS lookup limits.
Increase policy gradually
Start with p=none and ingest aggregate reports into a system that groups sources. Resolve unknown senders, apply quarantine to a small percentage, increase coverage and move to reject only after a measured observation period.
Test campaigns, aliases, forwarding and mailing lists separately because indirect flows can modify messages. Track delivery, complaints and authentication failures, and keep a tested DNS rollback plan.
Treat the domain as a managed asset
A new campaign or CRM provider should pass SPF, DKIM and DMARC checks before launch. Give each new subdomain an owner and a standard configuration rather than copying an arbitrary record from the parent domain.
Review reports, key age, unused senders and look-alike domains. DMARC reduces unauthorized use of the company name, but it does not replace malware filtering, account security or user awareness.

