Back to Blog
Email Security10 July 2026

What is DMARC and Why Every South African Business Needs It

Without DMARC, anyone can send emails pretending to be from your domain. Here's how DMARC, SPF and DKIM work together — and how to get to full enforcement without breaking your email.

Every day, South African businesses receive emails pretending to be from their bank, their suppliers, or even from themselves. Some of that impersonation works by forging a real company's email domain, and that is the specific problem DMARC is designed to solve.

DMARC is not optional. It is the foundation of email security for any business that takes its domain reputation and its clients' trust seriously.

What is DMARC?

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is an email authentication protocol that prevents cybercriminals from sending emails that appear to come from your domain.

Without DMARC, anyone can forge an email that looks like it came from your company. Your clients receive an invoice from "accounts@yourcompany.co.za" — sent by a fraudster. They pay the fraudster's bank account. The damage is done before anyone realises what happened.

DMARC is designed to stop exactly this kind of direct domain spoofing. When DMARC is properly configured and set to enforcement, you instruct receiving mail servers to quarantine or reject email that fails authentication. The receiving server still makes the final decision: the DMARC standard leaves the handling of each message to the receiver's local policy, and a receiver may accept failing mail even under a reject policy (RFC 9989). An enforced DMARC policy is what gives receivers a clear instruction to block forgeries of your domain.

The Three Pillars: SPF, DKIM and DMARC

DMARC builds on two existing email authentication standards.

SPF (Sender Policy Framework) specifies which mail servers are authorised to send email from your domain. Any email from a server not on your SPF list fails SPF authentication.

DKIM (DomainKeys Identified Mail) cryptographically signs your outgoing emails. Recipients can verify that the email actually came from your mail server and has not been tampered with in transit.

DMARC ties SPF and DKIM together and tells receiving mail servers what to do when an email fails authentication — do nothing, quarantine it to spam, or reject it outright. DMARC also sends you aggregate reports so you can see exactly who is sending email using your domain.

SPF and DKIM alone are not enough. Without DMARC, even if SPF and DKIM checks fail, there is no instruction to the receiving server about what to do with the email. It may still be delivered. DMARC is what enforces the rule.

Why DMARC Matters for South African Businesses

South Africa's banking risk information centre, SABRIC, reports that business email compromise and supplier mandate fraud "remained material risks" in 2025 (SABRIC Annual Crime Statistics 2025). Some of this fraud relies on forging a legitimate company's domain, which DMARC is designed to stop. Other techniques don't need to forge your domain at all.

It is important to be clear about what DMARC does not do. It protects your exact domain from being forged. On its own, it does not stop:

  • email sent from a genuine mailbox that has been compromised, because that mail really does come from the legitimate domain and passes authentication
  • lookalike domains, such as a domain one character different from yours
  • display-name tricks, where a trusted name is shown in front of an unrelated address, such as a free webmail account

The DMARC standard itself says it does not address lookalike domains or display names (RFC 9989). We cover the compromised-mailbox scenario, and the payment checks that catch it, in why a fraudulent email can come from a real supplier's address. DMARC is an important control against direct domain spoofing, not a complete defence against email fraud.

Under POPIA, your organisation is responsible for protecting information in your possession and for taking reasonable steps to prevent breaches. A successful phishing attack that uses your domain to compromise a client's information could expose you to POPIA liability — even if your own systems were never directly breached.

For businesses dealing with financial transactions, procurement, or client data, DMARC is increasingly a requirement from enterprise clients and government bodies, not a nice-to-have.

The Journey to Full Enforcement

DMARC implementation follows a phased approach:

Phase 1 — Monitor (p=none): DMARC is set to monitor-only. Emails still pass, but you receive reports showing all sources sending email from your domain. This gives visibility without risk.

Phase 2 — Quarantine (p=quarantine): Receiving servers are asked to treat email that fails DMARC authentication as suspicious, which usually means sending it to spam rather than the inbox. This begins protecting recipients without the risk of blocking legitimate email.

Phase 3 — Reject (p=reject): Full enforcement. Receiving servers are asked to reject email that fails DMARC. This is the strongest instruction you can give them to block forgeries of your domain, although each receiving server makes the final decision.

The journey from p=none to p=reject typically takes 4–12 weeks, depending on how many legitimate services send email from your domain — your email provider, CRM, marketing platform, accounting software, and so on.

How ROI Technologies Implements DMARC

ROI Technologies is a Sendmarc partner. Sendmarc is a South African DMARC management platform that provides real-time monitoring, reporting and policy management across your entire email environment.

Our process:

  1. DNS audit — we review your current SPF, DKIM and DMARC records
  2. Sendmarc deployment — DMARC monitoring is activated and reports begin flowing in
  3. Source discovery — we identify every legitimate service sending email from your domain
  4. Policy enforcement — once all legitimate sources are authorised, we move to p=reject
  5. Ongoing monitoring — Sendmarc continues to alert if any new sending sources appear

Frequently Asked Questions About DMARC

Does DMARC affect my outgoing email? Not if it is implemented correctly. The monitoring phase exists to ensure all your legitimate email sources are identified and authorised before any enforcement begins.

Do I need DMARC if I use Microsoft 365? Yes. Microsoft 365 sets up SPF and DKIM automatically only for your default onmicrosoft.com domain. For your own domain (for example, yourcompany.co.za), SPF must be configured in your DNS and DKIM signing must be switched on by your administrator. Microsoft states that "no DKIM signing occurs for outbound mail from custom domains" until this is done (Microsoft Learn). DMARC must also be configured separately in your DNS. Without DMARC, SPF and DKIM alone do not prevent spoofing of your domain.

How long does DMARC implementation take? Typically 4–12 weeks from setup to p=reject enforcement, depending on the complexity of your email environment. Simpler environments can reach full enforcement faster.

What is Sendmarc? Sendmarc is a South African DMARC management platform that provides visibility, reporting and policy management. ROI Technologies uses Sendmarc to implement and manage DMARC for our clients — from initial setup through to full enforcement.

What happens to spoofed emails after DMARC is enforced? At p=reject, you ask receiving mail servers to reject email that fails DMARC authentication before it reaches the inbox, and receivers that honour DMARC do so. Because each receiving server makes the final decision, DMARC is a strong protection against direct spoofing of your domain rather than a guarantee that no forged email ever arrives.

Contact ROI Technologies to get DMARC implemented for your domain.

Need IT or Cybersecurity help in South Africa?

Talk to ROI Technologies — Johannesburg-based and vendor-agnostic.

Contact Us