SPF
Sender Policy Framework — a DNS record that says which mail servers are authorised to send email on behalf of your domain. Prevents spoofing from unauthorised infrastructure.
Cyber Security · Email Auth
Cybercriminals impersonate your domain to trick your customers, suppliers, and staff. Managed DMARC, SPF, and DKIM lock down your email identity and give you visibility over every message sent in your name.
Free · No Signup
Enter your domain to instantly check whether it has a DMARC record — and whether the policy actually protects you.
How DMARC Works
Sender Policy Framework — a DNS record that says which mail servers are authorised to send email on behalf of your domain. Prevents spoofing from unauthorised infrastructure.
DomainKeys Identified Mail — a cryptographic signature added to every outgoing email. Proves the message wasn't tampered with in transit and originated from your infrastructure.
Ties SPF and DKIM together with a policy (none / quarantine / reject) and reporting. Tells receiving servers what to do with messages that fail authentication — and gives you visibility over every send in your name.
Why It Matters
Attackers can't impersonate your domain to phish your customers, suppliers, or staff.
DMARC is required by Google, Yahoo, some cyber insurance policies, and government tenders.
A single successful spoofing campaign can damage customer trust for years.
Reports show every service sending mail in your name — including shadow IT you didn't know about.
Authenticated mail lands in inboxes, not spam folders.
Managed monthly to catch new sender registrations, changes, and drift.
The Rollout
Audit your current SPF, DKIM, and DMARC records. Identify all legitimate senders across your organisation.
Deploy DMARC in reporting mode. Collect aggregate data on who's sending mail as you — legitimately and otherwise.
Fix SPF and DKIM for every legitimate sender identified. This is where the real work is.
Once all legitimate mail is authenticated, tighten policy to reject. Spoofed mail from your domain now bounces at the recipient.
No Pushy Sales
Book A Free 30-Minute Consultation
Talk to a Melbourne IT & cyber specialist about your business. No obligation, no pushy sales, no jargon — just useful advice.
Verified Reviews
Melbourne Businesses Trust Black Lantern
Real Google & Facebook reviews — verified via TrustIndex, updated automatically.
FAQs
Frequently Asked Questions
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks. Without it, attackers can spoof your domain and impersonate you to your customers, suppliers, and staff.
SPF says which servers are allowed to send email for your domain. DKIM signs outgoing emails cryptographically to prove they haven't been tampered with. DMARC ties the two together with a policy (none, quarantine, or reject) and reporting so you can see who's sending mail in your name.
Not if it's implemented properly. The standard rollout is to start with a p=none policy that monitors traffic without blocking anything, identify all legitimate senders (marketing platforms, CRMs, invoice systems), authenticate them properly, then progressively enforce. Rushing this step is the main cause of DMARC breaking legitimate mail.
Full setup of SPF, DKIM, and DMARC records; a managed reporting portal that turns cryptic XML aggregate reports into readable dashboards; ongoing sender identification and authentication; and policy tightening once we've verified no legitimate senders will be caught.
For a typical Melbourne SME, the journey from p=none monitoring to p=reject enforcement takes 60-90 days. Complex environments with many marketing platforms, third-party invoice senders, or acquired subsidiaries can take longer.
Increasingly, yes. Google and Yahoo require DMARC for bulk senders. Some cyber insurance policies now list DMARC enforcement as a prerequisite. Government and enterprise procurement often ask for it as part of email security controls.
Yes — Black Lantern's managed DMARC service is backed by a 24/7/365 helpdesk, which covers Australian business hours and every hour outside them, including weekends and public holidays. Our Melbourne office is at 35/477 Collins Street, Melbourne VIC 3000, and our support line on 1300 146 218 is answered around the clock by our own engineers, not an offshore call centre. Web enquiries are answered within 15 minutes during business hours.
Our average response time is under 5 minutes for critical issues, backed by contractual SLAs. Enquiries and requests raised through the website are answered within 15 minutes during Australian business hours, and by 9am the next business day outside them. Anything urgent can be escalated at any time on 1300 146 218, which is answered 24/7/365.
Black Lantern is a Melbourne-based managed service provider, with our office at 35/477 Collins Street in the Melbourne CBD, and we do not use offshore call centres. Our engineers, account managers and support staff work across Melbourne, London and the US, which is what gives clients genuine follow-the-sun coverage around the clock. Every ticket is handled by a real engineer who knows your environment rather than a scripted agent.
Managed DMARC monitoring is delivered as part of Black Lantern's managed cyber security service on fixed monthly per-user pricing, month-to-month with no lock-in contracts. Because every domain has a different number of legitimate senders and platforms to authenticate, we scope it against your actual environment rather than quoting a blanket rate — contact us for competitive pricing. We also provide a free IT and cyber security audit, with the report supplied either way, before you commit to anything.
Get In Touch
Talk To Black Lantern
Send us a message and we'll respond within 15 minutes during business hours. For urgent issues, call 1300 146 218 — we answer 24/7/365.