Until DMARC is enforced, anyone can send mail as your domain.
Most UAE domains we check either have no DMARC record or have one set to monitoring, which stops nothing at all. Meanwhile Gmail now requires DMARC from bulk senders, so the same neglect that leaves you spoofable is starting to affect whether your legitimate mail arrives.

- p=none stops nothingMonitoring is not protection
- 5,000 a dayGoogle bulk sender threshold
- Two problemsSpoofing, and deliverability
- Enforced safelyInventory senders before you block
Eight things that decide whether your domain can be abused.
SPF, and the ten lookup limit that silently breaks it
SPF lists which servers may send for your domain. The specification limits an SPF check to ten DNS lookups, and every included service counts. Organisations add a marketing platform, then a CRM, then a booking system, and at some point the record quietly exceeds the limit and stops evaluating correctly. Nothing announces this. We count the lookups and tell you where you actually stand.
DKIM, so the message itself is signed
DKIM attaches a cryptographic signature that survives normal forwarding better than SPF does, which matters because SPF breaks whenever mail is relayed. Every service that sends on your behalf needs its own DKIM key published in your DNS, and the common finding is that the main mail platform is signed while three secondary senders are not.
DMARC alignment, which is the part people miss
DMARC only passes if the domain a recipient sees in the From header aligns with the domain that passed SPF or DKIM. Google states this requirement directly for bulk senders. A service can pass SPF using its own domain and still fail DMARC for you, which is why a record can look correct while legitimate mail from your marketing platform fails. Alignment, not just presence, is what we check.
Your policy, and whether it does anything at all
A DMARC record with p=none tells receivers to take no action. It is a monitoring position and it is the right place to start, but a very large number of UAE domains have sat there for years while their owners believe they are protected. Protection begins at quarantine and is complete at reject. If your record says none, your domain is as spoofable as one with no record at all.
Reporting, so you can see who sends as you
DMARC reports are the reason the process works. Receivers send back aggregate data on every source claiming to be your domain, which reveals both the services you forgot you use and anybody abusing your name. Nobody reads raw report files, so the practical step is collecting them somewhere legible. Without this you are moving to enforcement blind, and that is how legitimate mail gets blocked.
A full inventory of who sends on your behalf
The genuine work in a DMARC project is not DNS, it is discovery. Marketing platform, CRM, invoicing system, HR portal, booking engine, support desk, e-signature service, the accountant who sends statements, that one server in the corner. Every one of them must be authenticated before you enforce, and each department will have forgotten at least one.
Subdomains, including ones you do not use
A domain with a strict policy and an unprotected subdomain leaves an obvious opening, and attackers try subdomains precisely because they are usually forgotten. Parked domains and old brand domains you still own matter too: if you own it and it can send mail, it can be used against you, and a domain you never send from should be locked down completely.
Deliverability, which is now the commercial driver
Google requires bulk senders, meaning around five thousand messages a day to Gmail addresses, to have DMARC in place with alignment, keep spam complaints below 0.3 percent, and offer one-click unsubscribe on marketing mail. All senders need SPF or DKIM, valid forward and reverse DNS, and TLS. Outlook has introduced comparable requirements for high-volume senders. Authentication has moved from a security nicety to a condition of delivery.
DMARC stops spoofing of your domain. It does not stop lookalikes.
This matters because most business email compromise in this region does not spoof your domain at all, and a page that implies otherwise would be selling you false comfort.
- What DMARC at enforcement genuinely prevents: somebody sending mail with your exact domain in the From address. That is a real attack, it is used against known brands, and enforcement closes it properly. It is worth doing for that reason alone.
- What it does not touch: an attacker registering a domain that looks like yours, differing by a hyphen, a swapped letter or a different ending, and authenticating it perfectly. Their DMARC will pass, because it is their domain. The invoice fraud that actually costs UAE businesses money usually arrives this way, or from a genuinely compromised mailbox at a supplier.
- So DMARC is one layer of several. The others are worth naming: user awareness of how invoice fraud actually works, a payment process where bank detail changes are verified by phone to a known number, external sender warnings, and monitoring for registrations of domains similar to yours. None of these is expensive.
- The honest summary is that DMARC is cheap, definite and limited. It closes one specific hole completely and leaves the more common attack untouched. Do it, do not stop there, and be suspicious of anyone selling it as the answer to phishing.
Four things that keep an enforcement project from breaking your mail.
We find the senders nobody remembers
The discovery work is where the value is. We use your DMARC reports plus interviews across finance, marketing, HR and operations, because IT typically knows about half the services sending as your domain. The half IT does not know about is exactly what breaks when you enforce, which is why projects that skip this stage get rolled back.
We move in stages, and we can reverse any of them
Monitoring first, then quarantine at a partial percentage, then increasing coverage, then reject. Each step is watched before the next, and each is reversible in the time it takes DNS to update. Going straight to reject is how a business discovers on a Sunday morning that its invoices have stopped arriving.
We tell you what this does not fix
DMARC at enforcement closes exact-domain spoofing and does nothing about lookalike domains or compromised supplier mailboxes, which is what most invoice fraud in this market actually uses. We say so, and we tell you what the other layers are, including the ones that cost nothing. Selling this as the answer to phishing would be misleading.
We leave you with reports somebody actually reads
Domains drift. A new marketing platform gets added, a supplier starts sending on your behalf, someone spins up a service and nobody tells IT. Ongoing report monitoring catches those before they either fail delivery or sit as an unauthenticated gap. We set this up so it is legible rather than a folder of XML nobody opens.
Six situations where this moves from housekeeping to urgent.
Any business that sends or receives payment instructions
Trading companies, contractors, professional services, anybody invoicing significant amounts. Invoice fraud is the most common financially damaging attack on UAE businesses, and while DMARC only closes the exact-domain half of it, that half is closed completely and permanently for the cost of some DNS records and careful discovery work.
An organisation sending marketing at volume
If you send anywhere near five thousand messages a day to Gmail addresses you are a bulk sender under Google rules, which means DMARC with alignment, spam complaints below 0.3 percent and one-click unsubscribe on marketing mail. Google has been clear that non-compliant mail faces rejection, so this has become a commercial deliverability question rather than only a security one.
A company whose brand is worth impersonating
Recognisable names get spoofed, and the damage lands on customers and partners rather than on you, which makes it harder to detect and worse for reputation. If your customers would plausibly act on an email that appeared to come from you, enforcement is not optional. Property, education, travel and financial brands in this market are targeted regularly.
A business whose mail has started going to spam
Frequently the first symptom people notice, and it often traces back to authentication rather than content. A broken SPF record that exceeded the lookup limit, a new sending service that was never authenticated, or missing alignment. This is a specific, diagnosable problem, and it is usually cheaper to fix than the deliverability consultancy people buy instead.
Travel, hospitality and anyone sending booking confirmations
High volumes of transactional mail to consumer mailboxes, which means Google and Yahoo rules apply directly, and confirmations that customers must receive for the business to function. Here a deliverability failure is not a marketing inconvenience, it is customers arriving without a booking reference and calling your support desk.
An organisation that has just been asked in a questionnaire
DMARC enforcement appears on client security questionnaires and insurer forms with increasing frequency, and it is one of the few items on those forms that is publicly verifiable. Anybody can look up your DNS and see whether your policy is enforced, so this is a question you cannot answer optimistically, which is a good reason to fix it before being asked.
Where UAE domains actually sit on email authentication.
| Feature | Enforced | Monitoring only, p=none | No DMARC record |
|---|---|---|---|
Exact-domain spoofing blocked | |||
You can see who sends as your domain | If reports are read | ||
All sending services inventoried | Partially | ||
SPF within the ten lookup limit | Often not | Often not | |
DKIM on every sending service | Main platform only | Rarely | |
Meets Google bulk sender requirements | Minimally | ||
Subdomains and parked domains protected | |||
Legitimate mail deliverability protected | At risk | At risk | |
Lookalike domain attacks prevented | |||
How common in the UAE market | Uncommon | Very common | Common in SMEs |
SPF, DKIM and DMARC, and the job each one has.
| SPF | DKIM | DMARC | |
|---|---|---|---|
| What it checks | Which servers may send | A signature on the message | Whether SPF or DKIM aligned |
| Survives forwarding | Often not | Usually yes | Depends on the other two |
| Tells receivers what to do on failure | No | No | Yes, this is its purpose |
| Provides reporting back to you | No | No | Yes, aggregate reports |
| Subject to a DNS lookup limit | Yes, ten in the specification | No | No |
| Needs configuring per sending service | Yes | Yes | Once for the domain |
| Required by Google for all senders | SPF or DKIM | SPF or DKIM | Bulk senders only |
| Stops exact-domain spoofing | Not alone | Not alone | Yes, at enforcement |
| Stops lookalike domains | No | No | No |
| Value of having it without the others | Partial | Partial | None, it depends on them |
Five stages, typically six to twelve weeks to enforcement.
- 1
Audit what exists today
Current SPF, DKIM and DMARC records for your main domain, every subdomain and every domain you own but do not use. We count SPF lookups against the ten-lookup specification limit, check DKIM per service, and establish whether your current policy does anything at all. This stage alone often explains a deliverability problem somebody has been chasing for months.
- 2
Turn on reporting and start watching
Publish or correct the DMARC record at monitoring, with reports collected somewhere legible. Then wait. The first two to four weeks of reports are the discovery: every source claiming to send as your domain, including the ones nobody remembered and, occasionally, somebody who should not be there at all.
- 3
Authenticate every legitimate sender
Each service gets SPF and DKIM configured correctly and, crucially, aligned so DMARC actually passes for it. Where a vendor cannot support alignment, we identify that early, because it is a decision for you rather than a technical detail: either the vendor changes, you change vendor, or that mail stream stays outside enforcement.
- 4
Move to enforcement in controlled steps
Quarantine at a partial percentage first, watched, then increased, then reject. Each step is reversible within a DNS update. We do not skip stages and we do not enforce on a Thursday afternoon. This is the part that goes wrong when it is rushed, and the failure is always commercial rather than technical.
- 5
Keep monitoring, because domains drift
A new platform gets bought, a department signs up for a tool, a supplier starts sending on your behalf. Ongoing report review catches these before they either fail to deliver or quietly sit unauthenticated. We can run this or hand it over with the reporting configured so it is genuinely readable.
“The reports found four services sending as our domain that nobody in IT knew about, including one set up by a marketing agency we stopped using two years ago. That agency could still send email as us. Finding that was worth the whole exercise before we even got to enforcement.”
What businesses ask about DMARC.
Fifteen checks, most of which you can run yourself today.
What your DNS says today
- Do you have a DMARC record at all?Look up _dmarc followed by your domain. Many UAE domains have none.
- If you have one, what is the policy set to?p=none is monitoring. It blocks nothing.
- How many DNS lookups does your SPF record require?The specification limit is ten, and exceeding it breaks evaluation.
- Is DKIM signing enabled on your main mail platform?Often enabled for the platform and missing for everything else.
- Do you have a subdomain policy, and are unused domains locked down?Attackers try subdomains because they are usually forgotten.
Before you enforce
- Are DMARC reports being collected anywhere readable?Enforcing without reports is enforcing blind.
- Have you listed every service that sends as your domain?Ask each department. Each one has forgotten at least one.
- Is each of those services authenticated and aligned?Passing SPF on the vendor domain is not alignment.
- Does anyone send from a personal address using your domain?Common with founders, agents and freelancers.
- Is there a rollback plan if legitimate mail starts failing?Move in stages. Never straight to reject.
What DMARC will not cover
- Are similar-looking domains being monitored?The attack DMARC cannot touch, and the one most used here.
- Do external emails carry a visible warning banner?Cheap, and effective against display-name impersonation.
- Does a bank detail change require phone verification?The single best control against invoice fraud.
- Do staff know how invoice fraud actually works?Specific examples beat generic awareness training.
- Would you notice a supplier mailbox being compromised?Their breach becomes your loss.
The pages around this one.
Microsoft 365 security audit
The other half of the email picture: your tenant configuration, mail flow rules, forwarding, and how far back your audit evidence actually reaches.
IT audit services in Dubai
The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.
Cybersecurity companies in Dubai
The broader security practice, including the layers that address the invoice fraud DMARC cannot reach.
Look up your own DMARC record before you do anything else.
It is public, it takes a minute, and the policy value tells you most of what you need to know. If it says none, or there is no record at all, that is worth fixing and we will tell you free what your current position looks like from the outside.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Cybersecurity Companies Dubai
Cyber buyer's guide, 7 services to evaluate
Managed Security Services
MSS on Microsoft Defender XDR and Sentinel
Microsoft Defender
Advanced endpoint and email threat protection
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification