DMARC · SPF · DKIM · Managed

Email was never designed to protect sender identity.

Without DMARC at enforcement, anyone can send convincing phishing from your domain to your clients, staff and suppliers. AI has made it faster, cheaper and more believable than ever.

We deploy and manage DMARC, SPF and DKIM on the Sendmarc platform, get you to full enforcement, and keep you there.

Free domain score

Check your domain right now.

Pop in your email address and we will run a live DMARC, SPF and DKIM score on your domain. No login, no sales call. The report shows where your impersonation, privacy and branding controls stand today, and one of our engineers will walk you through the gaps.

How we deliver this

Real Bytes + Sendmarc. DMARC, managed.

We build your email authentication on the Sendmarc platform, the same automation backing thousands of enterprises globally. You get the technology and the engineers who run it.

Powered by

Sendmarc

Platform

Intelligent automation that surfaces every sending source, flags misconfigurations and enforces policy across every domain you own.

Promise

Targeted move to full DMARC enforcement without breaking legitimate email flow. Most clients reach p=reject inside 90 days.

People

Hands-on Real Bytes engineers and Sendmarc DMARC experts working alongside your team. No raw XML reports landed on your desk.

The fix

DMARC is the global standard for email sender authentication.

It is backed by Google, Microsoft, Yahoo, the ACSC and regulators worldwide. It is the only control that proves to a receiving mail server that an email claiming to come from you is actually from you.

How DMARC works

Three checks. One outcome you control.

Every email claiming to come from your domain is tested against SPF, DKIM and DMARC alignment. You tell mailbox providers what to do when something fails.

Sender

user@yourdomain.com

Receiving mail server

Gmail, Microsoft, Yahoo

DNS authentication checks

SPF

Authorised IPs

DKIM

Signature key

DMARC

Alignment policy

Pass or fail decision

Pass

Delivered to inbox

Fail

Quarantined or rejected

Reports

Aggregate + forensic

Secure email gateways filter what comes in. DMARC controls what goes out in your name, stopping impersonation attacks your internal tools can't see. Source: Sendmarc.

Why DMARC

Four business outcomes, one DNS-level control.

DMARC isn't just a tick-box for the auditor. Done properly, it changes how your customers, your suppliers and the mailbox providers treat your domain.

Trust

Stop fake emails sent from your domain from being delivered. Recipients can trust that mail from your business is actually from your business.

Visibility

See every service sending on your behalf in one consolidated dashboard. Marketing platforms, CRMs, accounting tools and anything else attached to your domain.

Delivery

Strong authentication strengthens sender reputation. Legitimate mail is more likely to reach the inbox, not Junk or Quarantine.

Compliance

Meet the sender requirements set by Gmail, Yahoo and Microsoft, plus the ASD Essential Eight and SMB1001 guidance for Australian businesses.

Mailbox provider mandates

If you can't prove who you are, your email won't be delivered.

Since 2024, every major mailbox provider has tightened sender rules. Bulk email without DMARC is throttled, sent to Spam or rejected. This is no longer a security issue alone, it is a deliverability issue that hits your invoices, your newsletters and your support replies.

DMARC at p=quarantine or higher meets every provider's baseline.

Google (Gmail)

Enforced February 2024

Bulk senders to Gmail accounts must publish DMARC, align SPF or DKIM, and honour one-click unsubscribe. Mail that fails is rejected outright.

Yahoo Mail

Enforced February 2024

Mirrors the Google sender requirements. Bulk and transactional mail without DMARC is throttled or sent to Junk.

Microsoft (Outlook)

Enforced May 2025

Outlook.com, Hotmail and Live mailboxes now require SPF, DKIM and DMARC. Non-compliant bulk mail is routed to Junk or rejected.

Apple iCloud Mail

Enforced 2024 onwards

Aligns with the Gmail and Yahoo sender rules. DMARC is treated as a precondition for inbox placement.

Sources: Google Email Sender Guidelines, Yahoo Sender Best Practices, Microsoft High Volume Sender Requirements, Sendmarc 2025 reporting.

DMARC policy states

"We have DMARC" is not the same as protected.

DMARC has three policy states. Only one of them actually stops impersonation. Most Australian domains we audit are stuck at the first.

p=none

Monitoring

DMARC record published. Reports flow in. Nothing is blocked yet.

Legitimate mail delivered100%
Spoofed mail blocked0%

Spoofed mail still lands in customer inboxes.

p=quarantine

Quarantine

Failing mail is sent to Junk or Spam. Receivers treat it with suspicion but may still display it.

Legitimate mail delivered98%
Spoofed mail blocked75%

Partial protection. Some impersonation still reaches users.

p=reject

Enforcement

Failing mail is dropped at the receiver. Your brand cannot be spoofed by external senders.

Legitimate mail delivered99%
Spoofed mail blocked99%

The only state the ACSC and ASD recognise as protected.

Indicative block rates based on real client outcomes once Sendmarc is tuned. Actual figures depend on the cleanliness of legitimate sending sources before enforcement.

Breach detection

If your credentials are already on the dark web, DMARC won't help.

Most Australian businesses have no visibility of stolen company data circulating on criminal marketplaces. Breached credentials are how attackers bypass MFA, take over executive mailboxes and launch the BEC fraud DMARC was designed to stop.

33B+

Personal credentials stolen and circulating, including email and login details.

42M

Records exposed through data breaches in a recent 12-month window.

Source: Sendmarc Breach Detection, aggregated industry datasets.

Add breach monitoring

What we monitor

Hijacked credentials and personal info

Discover exposed passwords, email addresses and personal employee data leaked to the dark web before attackers weaponise them.

Device breaches

Monitor data stolen from compromised personal and corporate devices including keyloggers and info-stealer malware drops.

Service provider breaches

Surface third-party and supplier breaches that touch your data, so you can notify customers in line with the Notifiable Data Breaches scheme.

The sooner you know about compromised data, the faster you can rotate credentials, alert customers, and contain the damage.

Free 30 day trial

Run Check Point Harmony Email & Collaboration on your tenant for 30 days. On us.

Microsoft 365 and Google Workspace filtering catches commodity spam. It does not catch AI-crafted invoice fraud, supplier impersonation or business email compromise. Harmony's ML stack reads the way the message is written, the relationships in your tenant, and the behaviour around the click. Run it for 30 days, see what it finds, then decide.

  • Deployed by our engineers into your Microsoft 365 or Google Workspace tenant
  • AI and ML threat analytics running over real production mail flow
  • Daily detection summary plus a written findings report at the end of the trial
  • No credit card, no auto-renewal, no obligation to continue past 30 days

What the trial covers

30 days, end to end

Deployment in week one. Full ML telemetry from day two. Findings report in week four.

Sits alongside Microsoft or Google

API-based, no MX changes, no mail flow disruption, no outage risk to back out of.

Real findings, not a demo

We hand you a written report of every message the existing stack missed during the trial window.

Want the technical detail? Read the managed ESG service page or our AI email security guide.

Reference

The detail for the people who want the detail.

Attacker playbooks, the Australian regulatory frame and our 90-day delivery process in one place. Tap a tab to drill in.

What attackers do with an unprotected domain

Eight ways your domain is monetised the moment it's left open.

These aren't hypothetical. Every one of these tactics is in active use against Australian SMBs right now, accelerated by generative AI and cheap deepfake tooling.

Fake invoices and payment redirects

Spoofed mail from finance@yourcompany asking suppliers to update bank details. The most common variant of business email compromise in Australia.

Executive impersonation

Mail that looks like the CEO or CFO asking a junior staff member for urgent gift cards, wire transfers or sensitive documents.

Customer phishing

Order confirmations, delivery notices and account alerts sent to your customers from your real domain. Damages your brand trust permanently.

Credential harvesting

Login portals styled to match your tenant, linked from emails that pass basic checks because your domain is wide open.

Voice cloning follow-ups

AI-generated voice calls from a 'staff member' or 'supplier' confirming the email request. The combo bypasses staff suspicion.

Deepfake video escalations

Short fake video calls from a 'manager' authorising payments. Now cheap enough to deploy against mid-market Australian businesses.

Synthetic supplier identities

Fabricated supplier personas built across email, LinkedIn and ABN lookups to insert themselves into procurement workflows.

Supply chain pivot

Once one supplier is spoofed successfully, attackers reuse the playbook across their entire customer list. You may be next.

FAQs

The questions we get on every audit.

Stop letting attackers send mail in your name.

Most domains we audit have at least one critical email authentication gap. Find out where you stand before an attacker does. Free audit, no obligation, results the same week.

Delivering email security Brisbane, email security Hobart and Tasmania, and across Australia.