Who requires DMARC, and what actually satisfies them
DMARC compliance requirements
DMARC enforcement is required or expected by regulators and standards on both sides of the Atlantic. In the United States: PCI DSS v4.0 anti-phishing controls (mandatory since March 2025), CISA BOD 18-01 for federal agencies, HIPAA safeguards, NIST guidance, CIS Controls, and cyber insurance questionnaires. In Europe and the UK: NIS2, DORA for financial entities, GDPR Article 32 security measures, and the UK government's mandatory p=reject policy. A record at p=none satisfies almost none of them.
Requirement 5.4.1: mechanisms to detect and protect personnel against phishing attacks. DMARC, SPF, and DKIM are the named technical controls, mandatory in assessments since March 31, 2025.
What passes: Assessors look for DMARC at enforcement with aligned SPF and DKIM, not just a published record.
Binding Operational Directive: all second-level agency domains must publish DMARC with a policy of p=reject.
What passes: p=reject on every domain, including parked and non-mailing domains. MS-ISAC recommends the same for SLTT.
The Security Rule requires reasonable safeguards against threats to ePHI. Phishing is the leading breach vector, and email authentication is a baseline technical safeguard auditors expect to see.
What passes: Documented email authentication controls; DMARC enforcement demonstrates the safeguard is real, not aspirational.
Trustworthy Email (SP 800-177) recommends DMARC at enforcement alongside SPF, DKIM, MTA-STS, and TLS reporting.
What passes: DMARC at p=quarantine or p=reject with supporting authentication aligned.
Control 9.5: implement DMARC to lower the chance of spoofed or modified email from valid domains.
What passes: DMARC implemented and verifiable, referenced directly in many vendor security questionnaires.
Most carriers now ask about DMARC on their questionnaires. Answers affect premiums, coverage terms, and claims: a misrepresented control can jeopardize a payout.
What passes: A truthful "yes, enforced" answer, with our compliance report as documentation for your carrier.
The pattern on both continents: a record at p=none does not pass.
Assessors, regulators, carriers, and mailbox providers look for enforcement. That is exactly what the 90-day engagement delivers, with a compliance report you can hand to whoever is asking. All DMARC data is hosted in Germany, with a DPA available for GDPR.
Facing one of these deadlines?
15 minutes with an engineer. We pull your records live and tell you exactly how far you are from passing.
Get my free auditTake the call and your DMARC reporting is set up free for a year.