What problem does it solve?
Organizations that enable DMARC too aggressively block legitimate email, while those stuck at p=none get reports but no anti-spoofing protection. This Skill provides a safe, phased rollout methodology that authenticates every legitimate sending source before enforcement.
Core Features & Use Cases
- Phased Policy Progression: Move from p=none through p=quarantine to p=reject using gradual pct ramps (10% to 100%) with report review between steps.
- SPF/DKIM Alignment Guidance: Inventory sending sources, keep SPF under the 10-lookup limit, and configure DKIM signing for third-party platforms like Mailchimp, SendGrid, and Zendesk.
- Misconfiguration Detection: Identify common failures such as alignment mismatches, missing subdomain policies, and absent rollback plans.
- Use Case: A security team needs to meet Google and Yahoo bulk sender requirements. Follow the 3-6 month workflow to publish DMARC records, analyze aggregate reports with tools like EasyDMARC or dmarcian, and reach full p=reject without blocking legitimate mail.
Quick Start
Guide me through a phased DMARC rollout for our domain, starting from p=none monitoring and ending at full p=reject enforcement with subdomain protection.