DMARC, SPF & DKIM
Stop attackers spoofing your domain to your customers, suppliers and staff.

Protect your domain from being impersonated in email fraud
DMARC works with SPF and DKIM to stop criminals sending emails that look like they came from your domain. Most UK domains have it set to monitor only - which tells attackers exactly what they can get away with.
- Reduces supplier and customer invoice fraud
- Protects your brand from impersonation
- Improves deliverability of your genuine email
- Every legitimate sender is identified and authorised
- Policy moves beyond monitor to reject or quarantine
- Reports are reviewed instead of ignored
Is your domain only monitoring impersonation, or actively blocking it?
Ask us to move DMARC safely towards enforcement.
Understanding dmarc
Every time an attacker impersonates your domain to phish a customer, your brand pays the price. DMARC, SPF and DKIM tell the world's mail servers exactly which systems are allowed to send mail as you - and what to do with the rest. We get every UK customer to p=reject, the only DMARC policy that actually stops spoofing.
- Cyber Essentials & Cyber Essentials Plus
- ISO 27001:2022 Annex A controls
- NCSC 10 Steps to Cyber Security
- CIS Critical Security Controls v8
What we deploy and run
The concrete controls Telappliant configures, manages and reports on.

DMARC as run by a UK SOC and engineering team.
SPF, DKIM and DMARC records correctly configured for every sending domain.
Phased rollout: none -> quarantine -> reject without breaking legitimate mail.
DMARC reporting analysed weekly - not just records dropped in DNS and forgotten.
BIMI configuration once at p=reject for brand display in mailboxes.
Third-party sender onboarding (Mailchimp, HubSpot, ZenDesk etc).
Quarterly review as new tools and senders are added.
Why Telappliant
What you get with us that you don't get with the alternatives.
Delivered by a UK SOC and engineering team - no offshored ticketing.
Vendor-agnostic. We pick the right tool for your estate, then run it for you.
Mapped to Cyber Essentials, ISO 27001 and the NCSC 10 Steps from day one.
Fixed monthly price - no surprise hourly bills when something goes wrong.
The outcomes for your business
What changes for your team, your auditors and your insurer.
Attackers can no longer convincingly impersonate your domain.
Better deliverability for legitimate marketing and transactional mail.
Brand logo in supported mail clients via BIMI.
Insurer and supplier-questionnaire checkbox ticked.
Measured outcomes, not promises
3000+ UK organisations served and 100000+ end users supported.
< 60 minute average response on security incidents.
4000+ tickets resolved every month with measurable first-time-fix rates.
Vendor-fluent, not vendor-locked
We pick the right tool for your estate, then run it for you.
Trademarks are the property of their respective owners. We have no affiliation unless stated on our partners page.
Use cases
How this capability fits at different scales.
Get from no DMARC to p=reject in 6-8 weeks without breaking mail.
Bring every legitimate sender under one policy and reject the rest.
Continuous DMARC monitoring for brand and customer protection.
How this applies to organisations like yours
Recent situations we've worked through with UK businesses - find the one closest to yours.
Situation. Donors complaining about fake donation appeals from look-alike addresses.
Outcome. DMARC moved from none to reject in 90 days; spoofed mail now bounces at every major provider.
Situation. Candidates ghosting after fake job offers sent in the agency's name.
Outcome. BIMI logo in inbox plus DMARC enforcement restored sender trust.
Situation. FCA expects authenticated email for client communications.
Outcome. SPF, DKIM and DMARC at p=reject with quarterly evidence pack for compliance.
Situation. Six trading domains and a long tail of third-party senders to discover.
Outcome. Centralised reporting platform inventoried all senders, then enforced policy domain by domain.
Common questions
Related fundamentals & services
Microsoft 365 Security Hardening
Most SMEs already pay for the controls that cover dmarc. We help you turn Microsoft 365 Business Premium into a real security baseline - the front door into the wider Cyber Fundamentals portfolio.
Explore Microsoft 365 hardeningTalk to us about dmarc
A 30-minute call to scope what good looks like in your estate.
Talk to a UK technology partner who's done this for 20 years
Book a practical, no-pressure consultation. We'll review your current setup, show where AI communications, cloud telephony or managed IT could improve customer experience and reduce admin - and tell you straight if you don't need us.
- UK-based people, real account management
- Honest recommendations - even if it's not us
- Practical AI where it adds value, not hype
