SPEC · dmarc-enforcement
DMARC Enforcement Package
Google and Yahoo now require email authentication, and mail from unauthenticated domains is quietly going to spam or bouncing. If your DMARC policy is p=none or missing, your deliverability is on borrowed time.
Most DMARC projects fail one of two ways: the domain sits at p=none forever collecting reports nobody reads, or someone flips to p=reject on a Friday and breaks billing emails. The fix is boring and methodical: inventory every sender first, align each one, then ramp enforcement in steps while watching the reports. It takes about 60 days of elapsed time but only a few hours of yours.
What's included
- DMARC report collection and analysis for your domain
- Inventory of every service sending as your domain: app mail, marketing, billing, support desk, CRM, the works
- SPF and DKIM configuration for each legitimate source, aligned to pass DMARC
- Staged enforcement ramp: none, then quarantine at increasing percentages, then reject
- Verification at each step that legitimate mail still lands
- Tooling advice grounded in real vendor evaluations (PowerDMARC, Red Sift OnDMARC, Valimail)
What's not included
Fixed prices only work with honest boundaries. Here is where this project ends:
- Email marketing strategy or list management
- Mailbox migration or Google Workspace administration beyond authentication
- Ongoing report monitoring after handoff (the handoff doc covers how)
Deliverables
- Sender inventory worksheet, filled in
- Per-source SPF/DKIM alignment checklist, completed
- Enforcement ramp schedule with dates and what was verified at each step
- Final handoff doc: current state, how to add a new sender safely, what to watch
Timeline
About 60 days elapsed because DMARC reports and DNS changes need soak time. Your time investment is a kickoff call and a few short check-ins.
What I need from you
- DNS access (or someone who can apply the records I send)
- A list of tools you think send email for you (I will find the ones you forgot)