Back to Blog
Email Security10 July 2026

What is DMARC and Why Every South African Business Needs It

Without DMARC, anyone can send emails pretending to be from your domain. Here's how DMARC, SPF and DKIM work together — and how to get to full enforcement without breaking your email.

Every day, South African businesses receive emails pretending to be from their bank, their suppliers, or even from themselves. Email spoofing and business email compromise attacks cost South African companies hundreds of millions of rands annually — and the main reason they work is that most organisations have not implemented DMARC.

DMARC is not optional. It is the foundation of email security for any business that takes its domain reputation and its clients' trust seriously.

What is DMARC?

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is an email authentication protocol that prevents cybercriminals from sending emails that appear to come from your domain.

Without DMARC, anyone can forge an email that looks like it came from your company. Your clients receive an invoice from "accounts@yourcompany.co.za" — sent by a fraudster. They pay the fraudster's bank account. The damage is done before anyone realises what happened.

DMARC eliminates this. When DMARC is properly configured and enforced, emails that fail authentication are quarantined or rejected outright — they never reach your clients' inboxes.

The Three Pillars: SPF, DKIM and DMARC

DMARC builds on two existing email authentication standards.

SPF (Sender Policy Framework) specifies which mail servers are authorised to send email from your domain. Any email from a server not on your SPF list fails SPF authentication.

DKIM (DomainKeys Identified Mail) cryptographically signs your outgoing emails. Recipients can verify that the email actually came from your mail server and has not been tampered with in transit.

DMARC ties SPF and DKIM together and tells receiving mail servers what to do when an email fails authentication — do nothing, quarantine it to spam, or reject it outright. DMARC also sends you aggregate reports so you can see exactly who is sending email using your domain.

SPF and DKIM alone are not enough. Without DMARC, even if SPF and DKIM checks fail, there is no instruction to the receiving server about what to do with the email. It may still be delivered. DMARC is what enforces the rule.

Why DMARC Matters for South African Businesses

South Africa has some of the highest rates of business email compromise fraud in the world. Invoice fraud, CEO fraud and phishing attacks are routinely carried out by sending emails that appear to come from legitimate South African business domains.

Under POPIA, your organisation is responsible for protecting information in your possession and for taking reasonable steps to prevent breaches. A successful phishing attack that uses your domain to compromise a client's information could expose you to POPIA liability — even if your own systems were never directly breached.

For businesses dealing with financial transactions, procurement, or client data, DMARC is increasingly a requirement from enterprise clients and government bodies, not a nice-to-have.

The Journey to Full Enforcement

DMARC implementation follows a phased approach:

Phase 1 — Monitor (p=none): DMARC is set to monitor-only. Emails still pass, but you receive reports showing all sources sending email from your domain. This gives visibility without risk.

Phase 2 — Quarantine (p=quarantine): Emails that fail DMARC authentication go to spam rather than the inbox. This begins protecting recipients without the risk of blocking legitimate email.

Phase 3 — Reject (p=reject): Full enforcement. Emails that fail DMARC are rejected entirely. Your domain cannot be spoofed by anyone outside your authorised sending infrastructure.

The journey from p=none to p=reject typically takes 4–12 weeks, depending on how many legitimate services send email from your domain — your email provider, CRM, marketing platform, accounting software, and so on.

How ROI Technologies Implements DMARC

ROI Technologies is a Sendmarc partner. Sendmarc is a South African DMARC management platform that provides real-time monitoring, reporting and policy management across your entire email environment.

Our process:

  1. DNS audit — we review your current SPF, DKIM and DMARC records
  2. Sendmarc deployment — DMARC monitoring is activated and reports begin flowing in
  3. Source discovery — we identify every legitimate service sending email from your domain
  4. Policy enforcement — once all legitimate sources are authorised, we move to p=reject
  5. Ongoing monitoring — Sendmarc continues to alert if any new sending sources appear

Frequently Asked Questions About DMARC

Does DMARC affect my outgoing email? Not if it is implemented correctly. The monitoring phase exists to ensure all your legitimate email sources are identified and authorised before any enforcement begins.

Do I need DMARC if I use Microsoft 365? Yes. Microsoft 365 provides SPF and DKIM for your tenant, but DMARC must be configured separately in your DNS. Without DMARC, SPF and DKIM alone do not prevent spoofing of your domain.

How long does DMARC implementation take? Typically 4–12 weeks from setup to p=reject enforcement, depending on the complexity of your email environment. Simpler environments can reach full enforcement faster.

What is Sendmarc? Sendmarc is a South African DMARC management platform that provides visibility, reporting and policy management. ROI Technologies uses Sendmarc to implement and manage DMARC for our clients — from initial setup through to full enforcement.

What happens to spoofed emails after DMARC is enforced? At p=reject, emails that fail DMARC authentication are rejected by the receiving mail server before they reach the inbox. The fraudulent email never arrives.

Contact ROI Technologies to get DMARC implemented for your domain.

Need IT or Cybersecurity help in South Africa?

Talk to ROI Technologies — Johannesburg-based, certified, vendor-agnostic.

Contact Us