
THREAT‑WATCH
Glossary
DMARC
An email authentication standard that tells receiving mail servers what to do with messages that fail sender-verification checks.
DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on SPF and DKIM to let a domain owner specify how unauthenticated email claiming to be from their domain should be handled: quarantined, rejected, or allowed with reporting. Properly configured DMARC significantly reduces the effectiveness of email spoofing used in phishing and business email compromise.