Security service

Email Security & DMARC Implementation

By the NexusSec engineering team · 8 min read · Updated July 2026
We implement SPF, DKIM and DMARC so criminals cannot send email that appears to come from your domain — rolled out in stages so legitimate mail never stops flowing. Most organisations either have no DMARC at all, or have published a record that does nothing because it was left at monitor-only. We take you all the way to enforcement, safely.

Why this matters commercially

Business email compromise is one of the most financially damaging attacks Indian businesses face, and it rarely involves malware. An attacker sends an invoice that appears to come from your finance team, or an urgent payment request that appears to come from a director. Without email authentication, nothing technically prevents that message being delivered.

The damage is not only financial. When your customers receive convincing fraud in your name, the reputational cost outlasts the fraud itself.

The three standards

Explained fully in what is DMARC, in brief:

Why organisations get stuck

The two failure modes we encounter constantly: publishing p=reject immediately, which silently stops legitimate mail from systems nobody remembered — the CRM, the invoicing platform, the marketing tool; or publishing p=none and never progressing, which provides reports nobody reads and no protection whatsoever. A DMARC record at p=none stops exactly zero spoofing.

Our staged rollout

  1. Sender discovery. We identify every system legitimately sending mail as your domain — mail platform, CRM, ERP, invoicing, marketing, monitoring alerts, transactional mail. Nearly every organisation discovers senders it had forgotten.
  2. SPF. A single, correct record covering all legitimate senders, staying within DNS lookup limits — a common technical pitfall.
  3. DKIM. Signing enabled at each sending platform, with keys published and verified.
  4. DMARC at p=none. Published with reporting addresses. Delivery is unchanged; reports begin.
  5. Report analysis. Two to four weeks reviewing which sources pass, which fail, and which are unauthorised. We fix legitimate senders that fail.
  6. Progress to p=quarantine. Failing mail is treated as suspicious. Continued monitoring.
  7. Reach p=reject. Spoofed mail is refused outright — the point at which you are genuinely protected.
  8. Ongoing monitoring — new senders appear as the business adopts new tools, and must be authorised.

Additional hardening we implement

What DMARC does not solve

DMARC prevents impersonation of your domain. It does not stop phishing from lookalike domains, and it cannot help when a genuine mailbox is compromised — that mail authenticates correctly because it really is your account. Email filtering, multi-factor authentication on mailboxes, and user awareness remain necessary alongside it.

Cost and effort

This is DNS configuration and platform settings rather than a product purchase, which makes it one of the highest-return security controls available. The effort is concentrated in sender discovery and the monitoring period — typically six to ten weeks from start to enforcement, most of it waiting and verifying rather than active work.

Frequently asked questions

Why is our DMARC record not protecting us?

Most likely because it is set to p=none, which is monitor-only and instructs receivers to take no action on failures. It generates reports but stops no spoofing. Protection only begins at p=quarantine and is complete at p=reject. Many organisations publish p=none and never progress further.

Will DMARC block our legitimate email?

Not if implemented in stages. The risk arises when p=reject is published before every legitimate sender passes SPF or DKIM. We discover all senders first, then monitor at p=none for several weeks to confirm everything authenticates correctly, before progressing to quarantine and then reject.

How long does DMARC implementation take?

Typically six to ten weeks from start to full enforcement. Much of that is deliberate waiting — monitoring reports at p=none for two to four weeks, then again at p=quarantine — rather than active configuration work. Rushing the monitoring periods is what causes lost mail.

Does DMARC stop all phishing?

No. DMARC prevents attackers spoofing your exact domain. It does not stop phishing from lookalike domains that merely resemble yours, and it cannot help when a genuine mailbox has been compromised, because that mail authenticates legitimately. Email filtering, mailbox MFA and user awareness remain necessary.

What is the SPF lookup limit?

SPF records are limited to ten DNS lookups during evaluation. Exceeding this causes SPF to fail permanently, which then causes DMARC failures. Organisations using several third-party senders commonly breach this limit without realising. Flattening or restructuring the record resolves it, and we check this as part of implementation.

Stop criminals sending email as your business

NexusSec implements SPF, DKIM and staged DMARC enforcement for businesses across Navi Mumbai, Mumbai and India.

Request Email Security Review