Telappliant
Cyber Fundamentals - Network

DMARC, SPF & DKIM

Stop attackers spoofing your domain to your customers, suppliers and staff.

In plain English

Protect your domain from being impersonated in email fraud

DMARC works with SPF and DKIM to stop criminals sending emails that look like they came from your domain. Most UK domains have it set to monitor only - which tells attackers exactly what they can get away with.

Why this matters to your business
  • Reduces supplier and customer invoice fraud
  • Protects your brand from impersonation
  • Improves deliverability of your genuine email
What good looks like
  • Every legitimate sender is identified and authorised
  • Policy moves beyond monitor to reject or quarantine
  • Reports are reviewed instead of ignored
Conversation starter

Is your domain only monitoring impersonation, or actively blocking it?

Ask us to move DMARC safely towards enforcement.

Book a fundamentals review
What it is

Understanding dmarc

Every time an attacker impersonates your domain to phish a customer, your brand pays the price. DMARC, SPF and DKIM tell the world's mail servers exactly which systems are allowed to send mail as you - and what to do with the rest. We get every UK customer to p=reject, the only DMARC policy that actually stops spoofing.

Frameworks we align to
  • Cyber Essentials & Cyber Essentials Plus
  • ISO 27001:2022 Annex A controls
  • NCSC 10 Steps to Cyber Security
  • CIS Critical Security Controls v8
Features

What we deploy and run

The concrete controls Telappliant configures, manages and reports on.

Security analyst reviewing threat intelligence dashboards in a dim UK security operations centre
In the field

DMARC as run by a UK SOC and engineering team.

Feature

SPF, DKIM and DMARC records correctly configured for every sending domain.

Feature

Phased rollout: none -> quarantine -> reject without breaking legitimate mail.

Feature

DMARC reporting analysed weekly - not just records dropped in DNS and forgotten.

Feature

BIMI configuration once at p=reject for brand display in mailboxes.

Feature

Third-party sender onboarding (Mailchimp, HubSpot, ZenDesk etc).

Feature

Quarterly review as new tools and senders are added.

Advantages

Why Telappliant

What you get with us that you don't get with the alternatives.

Advantage

Delivered by a UK SOC and engineering team - no offshored ticketing.

Advantage

Vendor-agnostic. We pick the right tool for your estate, then run it for you.

Advantage

Mapped to Cyber Essentials, ISO 27001 and the NCSC 10 Steps from day one.

Advantage

Fixed monthly price - no surprise hourly bills when something goes wrong.

Benefits

The outcomes for your business

What changes for your team, your auditors and your insurer.

Benefit

Attackers can no longer convincingly impersonate your domain.

Benefit

Better deliverability for legitimate marketing and transactional mail.

Benefit

Brand logo in supported mail clients via BIMI.

Benefit

Insurer and supplier-questionnaire checkbox ticked.

Proof

Measured outcomes, not promises

3000+ UK organisations served and 100000+ end users supported.

< 60 minute average response on security incidents.

4000+ tickets resolved every month with measurable first-time-fix rates.

Vendors we deploy

Vendor-fluent, not vendor-locked

We pick the right tool for your estate, then run it for you.

Microsoft 365 DKIM/DMARCValimailEasyDMARCRed SiftProofpoint Email Fraud Defense

Trademarks are the property of their respective owners. We have no affiliation unless stated on our partners page.

Where it helps

Use cases

How this capability fits at different scales.

SME (25 users)

Get from no DMARC to p=reject in 6-8 weeks without breaking mail.

Multi-site (150 users)

Bring every legitimate sender under one policy and reject the rest.

Regulated (500 users)

Continuous DMARC monitoring for brand and customer protection.

Real-world scenarios

How this applies to organisations like yours

Recent situations we've worked through with UK businesses - find the one closest to yours.

Charity

Situation. Donors complaining about fake donation appeals from look-alike addresses.

Outcome. DMARC moved from none to reject in 90 days; spoofed mail now bounces at every major provider.

Recruitment agency

Situation. Candidates ghosting after fake job offers sent in the agency's name.

Outcome. BIMI logo in inbox plus DMARC enforcement restored sender trust.

Financial adviser

Situation. FCA expects authenticated email for client communications.

Outcome. SPF, DKIM and DMARC at p=reject with quarterly evidence pack for compliance.

Multi-brand group

Situation. Six trading domains and a long tail of third-party senders to discover.

Outcome. Centralised reporting platform inventoried all senders, then enforced policy domain by domain.

FAQs

Common questions

Start here

Microsoft 365 Security Hardening

Most SMEs already pay for the controls that cover dmarc. We help you turn Microsoft 365 Business Premium into a real security baseline - the front door into the wider Cyber Fundamentals portfolio.

Explore Microsoft 365 hardening

Talk to us about dmarc

A 30-minute call to scope what good looks like in your estate.

By submitting you agree to our privacy policy. We'll only use your details to contact you about your enquiry.

Talk to a UK technology partner who's done this for 20 years

Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.

  • UK-based people, real account management
  • Honest recommendations - even if it's not us
  • Practical AI where it adds value, not hype
Futuristic Telappliant technology network visual
Call us Book consultation