Shawn Freeman
CEO

One of your suppliers gets an email from your accounts team. Your domain, your signature block, your usual tone, and a polite note that the banking details have changed. They pay the invoice. The money is gone within the hour.
Nothing was hacked. Nobody clicked anything. No password was stolen. The attacker simply wrote your domain in the From field, and your own DNS quietly told the receiving mail server to deliver it anyway.
That instruction has a name: p=none. It is the monitoring setting in a DMARC record, and it is where the large majority of business domains have been parked since Google and Yahoo forced the issue in early 2024. Publishing it feels like progress. It gets you past the bulk sender checks. It also blocks exactly zero forged messages.
This post covers what p=none actually does, what it costs you to stay there, why the usual objection (that enforcement will break your email) is mostly avoidable, and the phased path to a policy that genuinely stops impersonation.
Three DNS records work together to prove an email really came from you. They are worth understanding in plain language, because the difference between them is where most of the confusion lives.
That instruction is the p= value, and it has three settings. With p=quarantine, failing mail goes to junk. With p=reject, failing mail is refused at the door and never reaches the recipient. With p=none, the receiving server takes no action at all. It delivers the forgery to the inbox and sends you a report about it afterwards.
💡 A DMARC record is public. It lives at _dmarc.yourdomain.com and anyone in the world can read it in about two seconds, including someone deciding which Calgary business is easiest to impersonate this week.
In February 2024, Google and Yahoo began requiring a DMARC record from high-volume senders. Microsoft followed on 5 May 2025, applying the same bar to anyone sending 5,000 or more messages a day to Outlook.com, Hotmail and Live addresses, with a hard 550 5.7.515 rejection for mail that does not comply.
Here is the detail that created the problem. All three providers set the minimum at p=none. A monitoring-only record satisfies the requirement. So a very large number of domains got a DMARC record published in a hurry by whoever was closest to the DNS panel, the deliverability warnings stopped, and the project was marked complete.
The record was published to protect email delivery, not to protect the domain. Those are two different tests, and passing the first one tells you nothing about the second.
⚠️ If your DMARC record was created in 2024 to fix a Gmail or Outlook delivery problem, there is a good chance it is still sitting at p=none today and nobody has read a single report since.
Business email compromise is the most expensive single incident type a Canadian small business is likely to face, and a spoofable domain makes it easy. The Canadian Anti-Fraud Centre recorded $704 million in reported fraud losses across Canada in 2025, the highest annual figure on record, with spear phishing and business email compromise approaching $68 million of that total. The CAFC estimates only 5 to 10 percent of fraud is ever reported, so the real number is several times higher.
The pattern is consistent: a message that appears to come from a supplier, an executive or a payroll contact, asking to update EFT details before the next run. When the From address is genuinely your domain rather than a lookalike, the request clears every mental check the recipient has.
A client who is defrauded by an email carrying your domain does not distinguish between your systems being breached and your domain being borrowed. The invoice looked like yours. The follow-up conversation is the same either way, and so is the effect on the relationship.
Mailbox providers score sender behaviour continuously. A domain that has sat on monitoring mode for two years while spoofed mail flows through it is a weaker signal than one at enforcement. That shows up as legitimate mail landing in junk, and it usually shows up first on the messages you care most about: quotes, invoices and onboarding emails.
Cyber insurance renewal questionnaires now ask about email authentication alongside multi-factor authentication and backups. Vendor security reviews and SOC 2 evidence requests are heading the same direction. Answering 'we have a DMARC record' when the policy is p=none is an answer that will not age well, and an inaccurate attestation on a renewal form is its own problem.
🚨 An attacker can query your DMARC policy in seconds, without touching your network. A domain sitting at p=none is a published signal that impersonation will work. Attackers check, and they pick accordingly.
This is the right thing to worry about, and it is the honest reason most domains never move. Skipping straight to p=reject on a Friday afternoon is how an organization discovers that its invoicing platform has been sending as the company domain, unsigned, for six years.
The risk is almost never your Microsoft 365 or Google Workspace mailboxes. Those authenticate correctly out of the box. The risk is the collection of systems nobody thinks of as email systems, quietly sending as you:
⚠️ SPF allows a maximum of 10 DNS lookups. Every new platform that asks you to 'just add one more include' pushes you toward that ceiling, and once you cross it SPF fails silently for every message you send. This is the single most common cause of a broken enforcement rollout.
The fix is sequencing, not courage. You find every legitimate sender first, get each one signing correctly with your domain, and only then tighten the policy. Done in that order, enforcement is uneventful.
📋 The sequence below typically runs six to ten weeks for a small business with a normal set of tools, and longer for organizations with many marketing platforms or business units.
✅ A percentage rollout on quarantine is the safety net that makes this a non-event. It lets you test enforcement on a slice of your mail volume while the rest is delivered normally.
An IT provider that manages your Microsoft 365 tenant has secured the mailbox: multi-factor authentication, conditional access, phishing filtering, alerting. All of that protects mail coming in and accounts being taken over. None of it protects your name in someone else's inbox. That job belongs to DNS, and it is the one piece routinely left at the default.
The gap is not technical difficulty. It is ownership. DMARC lives in DNS, DNS often sits with a web developer or a domain registrar login from 2014, and the reports arrive as XML that nobody has a tool to read. So it stays where it is. Meanwhile the federal government requires at least a quarantine policy on its own domains, and the Canadian Centre for Cyber Security's implementation guidance (ITSP.40.065) is explicit that only a reject policy delivers complete protection.
At Always Beyond, DMARC enforcement is part of the standard security baseline rather than a separate project. We take ownership of the DNS records, run the sender discovery, fix alignment across every platform in your stack, walk the policy up to reject, and review the reports at your regular technology review. It is deployed as a fleet-wide standard, which means it gets measured and it does not quietly drift back to a default.
💡 The Canadian federal government mandates SPF, DKIM and DMARC on its own email services. Only 9.2 percent of Canadian domains overall have reached full reject enforcement, which is a large gap between what the public sector considers baseline and what most private businesses have in place.
If you want to check where your organization stands, this is the standard we hold client domains to:
Yes, and that is the trap. All three accept a monitoring policy as the minimum for their bulk sender rules, so p=none keeps your mail flowing. It does not stop a single forged message. Meeting a deliverability requirement and being protected against impersonation are separate goals, and only one of them is covered.
For a business with a straightforward stack, six to ten weeks is typical, and most of that is the four-week reporting window needed to find every legitimate sender. Organizations with several marketing platforms, multiple brands or acquired domains take longer, mainly because the sender inventory is larger.
No, and it is important to be clear about that. DMARC protects domains you own. A message from a-lwaysbeyond.com is a different domain and passes its own checks. That threat is handled separately, through domain monitoring, defensive registrations, external sender warnings in Microsoft 365, and staff training. Enforcement removes the easier attack so that the harder one is all that is left.
Domain spoofing is not targeted in the way people picture it. Attackers scan for domains with weak or absent policies and work from the list. A 12-person firm with an unprotected domain and a supplier relationship worth six figures is a better prospect than a large enterprise at full enforcement.
Only indirectly. DMARC governs mail sent using your domain, which does stop the internal impersonation trick where a staff member appears to email a colleague. Inbound protection is a different layer: filtering, external sender labelling, multi-factor authentication and payment verification procedures. Both layers are needed.
Your IT provider, with your sign-off on the sender inventory. The work sits in DNS and across every platform that sends mail on your behalf, and it needs someone reading the reports monthly afterwards. If your provider has never raised DMARC with you, that is a fair question to ask at your next review.
Not sure what your domain is currently telling the world? Always Beyond checks your DMARC, SPF and DKIM posture, finds every system sending as you, and takes the policy to full enforcement without interrupting the mail you depend on. It is part of the security baseline we deploy and monitor across every client domain. Reach out to start the conversation.
See exactly how your current IT setup measures up to our Hack Free standards. Enter your business email to receive: