Every managed service provider sells email security, and almost every one of them has a client base where DMARC enforcement is still an intention rather than a published policy. Getting a single tenant to DMARC enforcement is a project you can finish in an afternoon. Getting forty tenants there — without breaking one invoice run, booking confirmation or payroll notification — is a programme. And programmes, unlike projects, need someone whose week is actually reserved for them.
That gap is where most MSPs sit right now. The DNS records exist. The reports arrive. Nothing moves. This guide sets out nine proven steps for taking DMARC enforcement across a whole client base, the sender types that reliably stall it, and a staffing model that gets it finished.
Table of contents

Why DMARC enforcement matters more in 2026
Two things changed the economics of email authentication. The first is that the large mailbox providers stopped asking politely. Google, Yahoo and Microsoft now apply bulk-sender rules to any domain sending roughly 5,000 messages a day or more, requiring SPF, DKIM and a published DMARC record, keeping spam complaints below the threshold they publish, and offering one-click unsubscribe on marketing mail. Non-compliant bulk mail is rejected at the SMTP level rather than filed in a spam folder, which means it never reaches a human at all.
The second is that publishing a record turned out to be the easy half. EasyDMARC’s 2026 adoption report, drawn from the top 1.8 million domains globally, found 937,931 domains — 52.1% — with DMARC implemented, up from 47.7% the year before. Only 411,935 of those had moved to an enforcement policy of p=quarantine or p=reject. Among the Fortune 500 the picture is far better, with 95% adoption and more than 80% at enforcement, which tells you this is a resourcing problem rather than a technical one. Large organisations do not have better DNS. They have someone assigned to it.
For an MSP, that asymmetry is an opportunity. DMARC enforcement is measurable, it produces evidence a client can show an insurer or an auditor, and it protects the one channel every business actually runs on. It is also, done properly, recurring work rather than a one-off ticket.
What DMARC enforcement actually means
DMARC builds on SPF and DKIM. SPF lists the servers allowed to send for your domain; DKIM signs messages cryptographically. DMARC ties both to the visible From address a recipient reads, tells receiving servers what to do when neither aligns, and asks them to report back. The mechanics are set out in RFC 7489, and the UK’s NCSC publishes plain-English implementation guidance in its email security and anti-spoofing collection.
The policy tag is where DMARC enforcement lives. A record with p=none asks for reports and instructs receivers to do nothing differently — useful for discovery, worthless as protection. p=quarantine sends failing mail to spam. p=reject tells receivers to refuse it outright. Only the last two count as DMARC enforcement, and only p=reject genuinely stops a criminal sending invoices in your client’s name.
This is why “we’ve done DMARC” is such a common and such a dangerous statement in a client review. A domain parked at p=none for eighteen months has all of the DNS work and none of the DMARC enforcement. Industry research has repeatedly found that the large majority of domains with a DMARC record never reach an enforcing policy, and the reason is almost always the same: nobody owned the middle part.
9 proven steps to DMARC enforcement across a client base
The sequence below is deliberately conservative. Rushing DMARC enforcement is how you end up rejecting a client’s own dispatch notifications on a Friday afternoon.
1. Build a sender inventory before you touch DNS
List every system that sends mail as the client: the tenant itself, the CRM, the accounting package, the marketing platform, the helpdesk, the scanner in the print room, the ancient line-of-business app on a server nobody logs into. This inventory is the single biggest predictor of whether DMARC enforcement will take three weeks or nine months.
2. Get SPF and DKIM right first
Flatten SPF records that exceed the ten-lookup limit, remove vendors the client stopped using years ago, and enable DKIM signing on every platform that supports it. DMARC enforcement inherits every weakness underneath it, so fixing alignment here saves rework later.
3. Publish p=none with aggregate reporting on
Start every tenant in monitoring mode with a valid rua address pointing at a reporting platform you control. Treat this as day one of the DMARC enforcement clock, not the finish line.
4. Read the reports weekly, not once
Aggregate reports are XML summaries of who sent mail claiming to be the client and whether it aligned. Reviewed weekly across a client base, patterns appear fast: a forgotten sending platform, a partner forwarding mail, an outright spoofing attempt. Reviewed once, they tell you nothing.
5. Authorise the legitimate senders you find
Every genuine sender the reports surface needs either an SPF include or DKIM signing, plus a note in the inventory. This is the unglamorous majority of the work and the part that makes DMARC enforcement safe rather than disruptive.
6. Move to p=quarantine and ramp the percentage
Use the pct tag to apply the policy to a slice of mail first, watch for a fortnight, then increase. Gradual ramping turns DMARC enforcement from a leap of faith into a controlled change with a rollback path.
7. Reach p=reject and hold it there
Once quarantine at full percentage produces no surprises, move to reject. Microsoft documents the configuration steps for tenants in its DMARC guidance for Defender for Office 365. Record the date, because that date is what the client’s insurer will ask about.
8. Cover subdomains and parked domains
Attackers move to whatever you left open. Set an explicit subdomain policy with sp=, and give every parked or defensive domain a null MX record and its own reject policy. Incomplete coverage is the most common way DMARC enforcement gets quietly undone.
9. Make it a monitored service, not a completed ticket
New SaaS platforms get bought, marketing tools get swapped, an acquisition adds a domain. Without ongoing report review, DMARC enforcement decays. Put it on the recurring service schedule with a named owner and a monthly evidence pack.
The long tail that stalls every rollout
Steps one to three take an afternoon per tenant. Steps four to six take months, and the reason is always the long tail of awkward senders. The multifunction printer that scans to email through an on-premises relay. The appointment reminder service a practice manager signed up for in 2019 and expensed personally. The accounting system that sends statements from a static IP that changed when the client moved office. The recruitment partner who forwards CVs in a way that breaks alignment.
None of these is difficult. All of them require a conversation with a person who does not work in IT, a change made in a portal nobody has the password for, and a follow-up two weeks later to confirm it worked. Multiply that by forty tenants and you have the real cost of DMARC enforcement — not engineering hours, but sustained, patient chasing over UK business hours.
This is precisely the work that loses to the ticket queue. An engineer with a P1 open is never going to spend Thursday morning emailing a client’s bookkeeper about a statement run. So the DMARC enforcement programme slips a week, then a month, then off the plan entirely, and every tenant sits at p=none looking compliant on the dashboard.
Staffing DMARC enforcement without pulling your team off tickets
The fix is not another policy document. It is dedicated capacity: someone whose job description is the programme, working the same hours as the clients they need to chase. That is a poor use of an expensive senior engineer and an excellent use of outstaffed capacity.
This is the model OutsourceZA was built for. South Africa gives UK and EU MSPs a deep pool of skilled, English-first technical talent at a typical saving of 40–60% against local hires, in a timezone that overlaps the full UK working day — so report review, client calls and vendor chasing happen live rather than in an overnight handover. Our engineers are MSP-ready, comfortable in RMM and PSA tooling and in multi-tenant Microsoft 365 estates, which is exactly the environment DMARC enforcement lives in.
Outstaffing also matches the shape of the work. A DMARC enforcement programme is heavy for a quarter and light thereafter, so you scale a dedicated engineer up for the rollout and retain them for the monthly monitoring. You keep the client relationship, the tooling and the standards; you add the hours. If you would rather see the calibre of the people first, our current technical roles give a fair sense of the bench.
Done this way, DMARC enforcement stops being the item that rolls over on every quarterly plan and becomes a service line with evidence attached. If you want to talk through what that would look like across your own client base, get in touch.
Frequently asked questions
How long does DMARC enforcement take for one tenant?
For a simple tenant sending only from Microsoft 365, two to four weeks including a monitoring period. For a client with a dozen third-party senders, three to six months is realistic. The variable is the sender inventory, not the DNS work.
Is p=quarantine good enough, or must we reach p=reject?
Quarantine counts as enforcement and is a genuine improvement, but spoofed mail still lands in the spam folder where a determined recipient can retrieve it. Reject is the goal; quarantine is the staging post on the way there.
Will DMARC enforcement break our client’s legitimate email?
Not if you follow the sequence. Every message that fails after you reach reject is one you did not authorise, which is why the monitoring period and the percentage ramp matter so much. Skipping them is what causes outages.
Do small clients under the bulk-sender threshold still need this?
Yes. The 5,000-messages-a-day threshold governs whether the large providers reject your mail, not whether criminals will impersonate your domain. Invoice fraud targets small firms precisely because they are unprotected, and DMARC enforcement is one of the cheapest controls available to them.
Who should own DMARC enforcement in an MSP?
A named individual with recurring scheduled hours, not the on-call rota. The work is steady and low-drama, which makes it ideal for dedicated outstaffed capacity working UK hours alongside your service desk. You can read more about how we work on our about page.
Book your consultation
Book a chat with Niel or Johan so we can understand exactly what (and who) you need for your business to succeed. It’s also a great time to ask any questions you may have. See you soon!