---
title: "DMARC Compliance Requirements | UseDMARCReport"
description: "Which regulations and standards require DMARC in the US and Europe: PCI DSS v4.0, CISA BOD 18-01, HIPAA, NIST, CIS, cyber insurance, NIS2, DORA, GDPR Article 32, and the UK government p=reject mandate."
image: "https://usedmarcreport.com/images/og-default.png"
canonical: "https://usedmarcreport.com/compliance/"
---

Who requires DMARC, and what actually satisfies them

# DMARC compliance requirements

DMARC enforcement is required or expected by regulators and standards on both sides of the Atlantic. In the United States: PCI DSS v4.0 anti-phishing controls (mandatory since March 2025), CISA BOD 18-01 for federal agencies, HIPAA safeguards, NIST guidance, CIS Controls, and cyber insurance questionnaires. In Europe and the UK: NIS2, DORA for financial entities, GDPR Article 32 security measures, and the UK government's mandatory p=reject policy. A record at p=none satisfies almost none of them.

United States Europe & UK 

PCI DSS v4.0 Any organization that stores, processes, or transmits cardholder data 

Requirement 5.4.1: mechanisms to detect and protect personnel against phishing attacks. DMARC, SPF, and DKIM are the named technical controls, mandatory in assessments since March 31, 2025.

**What passes:** Assessors look for DMARC at enforcement with aligned SPF and DKIM, not just a published record.

CISA BOD 18-01 US federal executive-branch agencies; the de facto bar for state, local, tribal, and territorial government 

Binding Operational Directive: all second-level agency domains must publish DMARC with a policy of p=reject.

**What passes:** p=reject on every domain, including parked and non-mailing domains. MS-ISAC recommends the same for SLTT.

[DMARC for government teams →](/government/)

HIPAA Covered entities and business associates handling PHI 

The Security Rule requires reasonable safeguards against threats to ePHI. Phishing is the leading breach vector, and email authentication is a baseline technical safeguard auditors expect to see.

**What passes:** Documented email authentication controls; DMARC enforcement demonstrates the safeguard is real, not aspirational.

NIST SP 800-177 / 800-53 Organizations aligning to NIST guidance, including federal contractors 

Trustworthy Email (SP 800-177) recommends DMARC at enforcement alongside SPF, DKIM, MTA-STS, and TLS reporting.

**What passes:** DMARC at p=quarantine or p=reject with supporting authentication aligned.

CIS Controls v8 Organizations using CIS benchmarks, common in insurance and vendor reviews 

Control 9.5: implement DMARC to lower the chance of spoofed or modified email from valid domains.

**What passes:** DMARC implemented and verifiable, referenced directly in many vendor security questionnaires.

Cyber insurance Anyone renewing or applying for cyber coverage 

Most carriers now ask about DMARC on their questionnaires. Answers affect premiums, coverage terms, and claims: a misrepresented control can jeopardize a payout.

**What passes:** A truthful "yes, enforced" answer, with our compliance report as documentation for your carrier.

[DMARC for cyber insurance →](/insurance/)

NIS2 Directive Essential and important entities across 18 sectors in the EU, plus many of their suppliers 

Requires basic cyber-hygiene practices and security measures proportionate to risk. ENISA implementation guidance names DMARC, SPF, and DKIM among the expected email security controls. National transpositions have been in force since October 2024, with management personally liable for non-compliance.

**What passes:** Documented, working email authentication; enforcement is what makes the control auditable.

DORA Banks, insurers, investment firms, and their critical ICT providers in the EU 

The Digital Operational Resilience Act (applying since January 2025) requires protective measures against ICT risk, and phishing and spoofing sit at the top of the financial-sector threat list.

**What passes:** Email authentication documented inside your ICT risk-management framework, at enforcement.

GDPR Art. 32 Anyone processing EU personal data 

Requires technical and organisational measures appropriate to the risk, taking into account the state of the art. Spoofing-enabled breaches routinely draw supervisory scrutiny, and email authentication is unambiguously state of the art.

**What passes:** DMARC enforcement as a demonstrable Article 32 measure; it also shortens breach-notification arguments.

UK Government / NCSC UK public sector, and suppliers who want to keep landing in government inboxes 

The UK government's Secure Email policy has required DMARC at p=reject on gov.uk domains since 2016, monitored through NCSC Mail Check. The same blueprint is NCSC's published recommendation for every UK organisation.

**What passes:** p=reject for public bodies; enforcement with aligned SPF/DKIM for everyone else.

Cyber Essentials & UK insurers UK organisations certifying Cyber Essentials or renewing UK cyber coverage 

NCSC anti-spoofing guidance sits behind the certification questions, and UK carriers increasingly ask for DMARC alongside MFA and backups on their questionnaires.

**What passes:** DMARC implemented and verifiable; "planned" does not score.

Google, Yahoo & Microsoft Everyone sending to Gmail, Yahoo, or Microsoft mailboxes, on either continent 

Bulk-sender rules (rolling out since 2024) require DMARC for high-volume senders, and all three providers increasingly junk or reject unauthenticated mail at any volume.

**What passes:** DMARC published and passing with aligned SPF or DKIM; enforcement protects your deliverability as the rules tighten.

The pattern on both continents: a record at p=none does not pass.

Assessors, regulators, carriers, and mailbox providers look for enforcement. That is exactly what the 90-day engagement delivers, with a compliance report you can hand to whoever is asking. All DMARC data is hosted in Germany, with a DPA available for GDPR.

## Facing one of these deadlines?

15 minutes with an engineer. We pull your records live and tell you exactly how far you are from passing.

[Get my free audit](/demo/) 

Take the call and your DMARC reporting is set up free for a year.

```json
{"@context":"https://schema.org","@type":"Organization","name":"UseDMARCReport","url":"https://usedmarcreport.com","logo":{"@type":"ImageObject","url":"https://usedmarcreport.com/logo.png"},"description":"Expert-led DMARC implementation that gets your domain to enforcement in 90 days. Guaranteed. We run the project, your team makes the DNS changes. SOC 2 Type 2 certified. 50,000+ domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.g2.com/products/dmarc-report/reviews","https://www.linkedin.com/company/duocircle","https://duocircle.com","https://dmarcreport.com","https://www.cisecurity.org/services/cis-cybermarket/duocircle"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://usedmarcreport.com/demo/"},"knowsAbout":["DMARC Implementation","DMARC Enforcement","Email Authentication","SPF","DKIM","MTA-STS","BIMI","Email Security"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"UseDMARCReport","url":"https://usedmarcreport.com","description":"Expert-led DMARC implementation that gets your domain to enforcement in 90 days. Guaranteed. We run the project, your team makes the DNS changes. SOC 2 Type 2 certified. 50,000+ domains.","publisher":{"@type":"Organization","name":"UseDMARCReport","url":"https://usedmarcreport.com","logo":{"@type":"ImageObject","url":"https://usedmarcreport.com/logo.png"},"description":"Expert-led DMARC implementation that gets your domain to enforcement in 90 days. Guaranteed. We run the project, your team makes the DNS changes. SOC 2 Type 2 certified. 50,000+ domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"WebPage","name":"DMARC Compliance Requirements","url":"https://usedmarcreport.com/compliance/","description":"DMARC enforcement is required or expected by regulators and standards on both sides of the Atlantic. In the United States: PCI DSS v4.0 anti-phishing controls (mandatory since March 2025), CISA BOD 18-01 for federal agencies, HIPAA safeguards, NIST guidance, CIS Controls, and cyber insurance questionnaires. In Europe and the UK: NIS2, DORA for financial entities, GDPR Article 32 security measures, and the UK government's mandatory p=reject policy. A record at p=none satisfies almost none of them.","speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
