Skip to main content

Who requires DMARC, and what actually satisfies them

DMARC compliance requirements

DMARC enforcement is required or expected by regulators and standards on both sides of the Atlantic. In the United States: PCI DSS v4.0 anti-phishing controls (mandatory since March 2025), CISA BOD 18-01 for federal agencies, HIPAA safeguards, NIST guidance, CIS Controls, and cyber insurance questionnaires. In Europe and the UK: NIS2, DORA for financial entities, GDPR Article 32 security measures, and the UK government's mandatory p=reject policy. A record at p=none satisfies almost none of them.

PCI DSS v4.0 Any organization that stores, processes, or transmits cardholder data

Requirement 5.4.1: mechanisms to detect and protect personnel against phishing attacks. DMARC, SPF, and DKIM are the named technical controls, mandatory in assessments since March 31, 2025.

What passes: Assessors look for DMARC at enforcement with aligned SPF and DKIM, not just a published record.

CISA BOD 18-01 US federal executive-branch agencies; the de facto bar for state, local, tribal, and territorial government

Binding Operational Directive: all second-level agency domains must publish DMARC with a policy of p=reject.

What passes: p=reject on every domain, including parked and non-mailing domains. MS-ISAC recommends the same for SLTT.

DMARC for government teams →

HIPAA Covered entities and business associates handling PHI

The Security Rule requires reasonable safeguards against threats to ePHI. Phishing is the leading breach vector, and email authentication is a baseline technical safeguard auditors expect to see.

What passes: Documented email authentication controls; DMARC enforcement demonstrates the safeguard is real, not aspirational.

NIST SP 800-177 / 800-53 Organizations aligning to NIST guidance, including federal contractors

Trustworthy Email (SP 800-177) recommends DMARC at enforcement alongside SPF, DKIM, MTA-STS, and TLS reporting.

What passes: DMARC at p=quarantine or p=reject with supporting authentication aligned.

CIS Controls v8 Organizations using CIS benchmarks, common in insurance and vendor reviews

Control 9.5: implement DMARC to lower the chance of spoofed or modified email from valid domains.

What passes: DMARC implemented and verifiable, referenced directly in many vendor security questionnaires.

Cyber insurance Anyone renewing or applying for cyber coverage

Most carriers now ask about DMARC on their questionnaires. Answers affect premiums, coverage terms, and claims: a misrepresented control can jeopardize a payout.

What passes: A truthful "yes, enforced" answer, with our compliance report as documentation for your carrier.

DMARC for cyber insurance →

The pattern on both continents: a record at p=none does not pass.

Assessors, regulators, carriers, and mailbox providers look for enforcement. That is exactly what the 90-day engagement delivers, with a compliance report you can hand to whoever is asking. All DMARC data is hosted in Germany, with a DPA available for GDPR.

Facing one of these deadlines?

15 minutes with an engineer. We pull your records live and tell you exactly how far you are from passing.

Get my free audit

Take the call and your DMARC reporting is set up free for a year.