Thereโs a chance youโre familiar with email. Electronic mail has been used increasingly worldwide since itโs inception in the 1970s; and here in 2025 itโs an almost indispensable necessity both in business and modern-day life. With emailโs prevalence in our society as a powerful communication tool, itโs also one of the most abused mediums by cybercriminals. New Zealand Organizations have seen a sharp rise in email impersonation scams across recent years, with threat actors sending send fraudulent messages that appear to come from trusted domains.
DMARC is one of the most effective defences against this type of attack, yet many NZ businesses are yet to implement, or perhaps even be aware of it.
If your business uses itโs own domain for email (e.g. @yourcompany.co.nz), this is something you should know about.
What Is DMARC?
DMARC stands for Domain-based Message Authentication, Reporting, and Conformance. Itโs a protocol that helps protect your email domain from being used for spoofing or phishing cyberattacks.
In simple terms, DMARC allows receiving mail servers (like Gmail, Outlook, etc.) to verify whether messages that claim to come from your domain are genuinely authorised by you. If not, those messages can be marked as suspicious, quarantined, or rejected altogether.
DMARC works in conjunction with two existing authentication systems:
ยท SPF (Sender Policy Framework): Defines which servers are allowed to send email on behalf of your domain.
ยท DKIM (DomainKeys Identified Mail): Adds a digital signature to verify that messages werenโt altered in transit.
Together, these three mechanisms make it much harder for cybercriminals to impersonate your domain or send fake invoices and payment requests under your business name.
Why DMARC Matters for NZ Businesses
Phishing (pronounced โfishingโ) is considered one of the most basic, widespread, and effective methods for committing cybercrime, often through convincing but fake supplier or management/executive emails. These campaigns can go even deeper through targeting and reconnaissance to become โspear phishingโ, or further again to focus exclusively on high-profile, senior executives within a company in an act known as โwhalingโ.
NCSC NZ attributed financial losses of $7.8million locally, due to cybercrime in Q1 2025. This was a 14.7% increase from the previous quarter and was the second-highest quarterly total ever recorded by the NCSC.
Without DMARC, anyone can technically send an email that appears to come from your domain. For example, an attacker could send a message that looks like itโs from [email protected] asking a customer to change payment details.
Implementing DMARC doesnโt just stop attackers from doing this โ it also:
ยท Protects your brand reputation by preventing misuse of your domain.
ยท Improves email deliverability (messages you send are less likely to be flagged as spam).
ยท Provides visibility through reporting, so you can see whoโs sending mail on behalf of your domain.
For SMEs that rely on customer trust, DMARC isnโt just an IT concern โ itโs a business safeguard.
Getting Started with DMARC
The good news is that setting up DMARC doesnโt require overhauling your entire email system, it does need careful configuration to avoid interrupting legitimate mail. There are some common pitfalls to avoid, such as rushing to turn DMARC on in โrejectโ mode straight away. This can lead to problems if certain legitimate senders (like your invoicing system or marketing platform) arenโt configured correctly.
A well-planned rollout ensures your real messages continue to flow smoothly while protecting against threat actors.
If your business domain doesnโt yet have DMARC in place, or youโre unsure whether your configuration is working as intended, get in touch. Weโre available to discuss your current configuration and necessary steps to implement DMARC on your domain with a robust set of tools.
We can:
ยท Review your current domain authentication setup.
ยท Help implement SPF, DKIM, and DMARC safely.
ยท Monitor and fine-tune your configuration to ensure consistent email delivery and security.
Why Itโs Worth Doing Now
Globally, email providers are tightening authentication requirements. Google and Yahoo, for instance, now require DMARC (and related standards) for bulk senders โ and these expectations will continue to expand.
For NZ SMEs, implementing DMARC is becoming a baseline best practice, much like using antivirus software or multifactor authentication. Itโs not just about compliance โ itโs about credibility and customer trust.
Protect your domain, your reputation, and your customers โ start by making sure your business email is truly your own.
