DMARC (Domain-based Message Authentication, Reporting, and Conformance) Policy


1. Purpose: This policy outlines the implementation and enforcement of DMARC (Domain-based Message Authentication, Reporting, and Conformance) for The purpose of this policy is to enhance email security, prevent email spoofing, and protect our organization and stakeholders from phishing attacks.

2. Scope: This policy applies to all email communication originating from email like, etc.

3. DMARC Configuration:

  • DMARC Record: A DMARC DNS record will be published for The record will be configured as follows:
    v=DMARC1; p=quarantine;;; sp=reject
    (Explanation: The policy is set to 'quarantine' for suspicious emails, aggregate reports are sent to the specified email address, forensic reports are sent to the specified email address, and subdomain policy is set to 'reject'.)

4. DMARC Reporting:

  • Aggregate Reports (RUA):

    • Aggregate reports will be sent to on a regular basis.
    • is responsible for monitoring and analyzing these reports.
  • Forensic Reports (RUF):

    • Forensic reports will be sent to when unauthorized or suspicious activity is detected.
    • is responsible for investigating and taking appropriate action.

5. Monitoring and Enforcement:

  • Regular monitoring of DMARC reports will be conducted to identify and mitigate any anomalies.
  • The IT Security team is responsible for enforcing DMARC policies and taking corrective actions in case of policy violations.

6. Policy Review:

  • This DMARC policy will be reviewed annually or as necessary to ensure its effectiveness and relevance.
  • Any changes to the DMARC policy will be communicated to relevant stakeholders.

7. Training and Awareness:

  • All employees and stakeholders will receive training and awareness programs on email security and the importance of DMARC.
  • Information on recognizing and reporting suspicious emails will be regularly communicated.

8. Exceptions:

  • Exceptions to this DMARC policy may be granted in exceptional cases, subject to approval from the IT Security team.

9. Contact Information: For any questions or concerns related to DMARC, please contact [Email Address].

10. Compliance: Non-compliance with this DMARC policy may result in disciplinary actions, as outlined in the Privacy Policy.

11. Effective Date: This DMARC policy is effective as of January 9, 2024.

