Email was never designed to protect sender identity.
Without DMARC at enforcement, anyone can send convincing phishing from your domain to your clients, staff and suppliers. AI has made it faster, cheaper and more believable than ever.
We deploy and manage DMARC, SPF and DKIM on the Sendmarc platform, get you to full enforcement, and keep you there.
Free domain score
Check your domain right now.
Pop in your email address and we will run a live DMARC, SPF and DKIM score on your domain. No login, no sales call. The report shows where your impersonation, privacy and branding controls stand today, and one of our engineers will walk you through the gaps.
How we deliver this
Real Bytes + Sendmarc. DMARC, managed.
We build your email authentication on the Sendmarc platform, the same automation backing thousands of enterprises globally. You get the technology and the engineers who run it.
Powered by
Sendmarc
Platform
Intelligent automation that surfaces every sending source, flags misconfigurations and enforces policy across every domain you own.
Promise
Targeted move to full DMARC enforcement without breaking legitimate email flow. Most clients reach p=reject inside 90 days.
People
Hands-on Real Bytes engineers and Sendmarc DMARC experts working alongside your team. No raw XML reports landed on your desk.
The fix
DMARC is the global standard for email sender authentication.
It is backed by Google, Microsoft, Yahoo, the ACSC and regulators worldwide. It is the only control that proves to a receiving mail server that an email claiming to come from you is actually from you.
How DMARC works
Three checks. One outcome you control.
Every email claiming to come from your domain is tested against SPF, DKIM and DMARC alignment. You tell mailbox providers what to do when something fails.
Sender
user@yourdomain.com
Receiving mail server
Gmail, Microsoft, Yahoo
DNS authentication checks
SPF
Authorised IPs
DKIM
Signature key
DMARC
Alignment policy
Pass
Delivered to inbox
Fail
Quarantined or rejected
Reports
Aggregate + forensic
Secure email gateways filter what comes in. DMARC controls what goes out in your name, stopping impersonation attacks your internal tools can't see. Source: Sendmarc.
Why DMARC
Four business outcomes, one DNS-level control.
DMARC isn't just a tick-box for the auditor. Done properly, it changes how your customers, your suppliers and the mailbox providers treat your domain.
Trust
Stop fake emails sent from your domain from being delivered. Recipients can trust that mail from your business is actually from your business.
Visibility
See every service sending on your behalf in one consolidated dashboard. Marketing platforms, CRMs, accounting tools and anything else attached to your domain.
Delivery
Strong authentication strengthens sender reputation. Legitimate mail is more likely to reach the inbox, not Junk or Quarantine.
Compliance
Meet the sender requirements set by Gmail, Yahoo and Microsoft, plus the ASD Essential Eight and SMB1001 guidance for Australian businesses.
Mailbox provider mandates
If you can't prove who you are, your email won't be delivered.
Since 2024, every major mailbox provider has tightened sender rules. Bulk email without DMARC is throttled, sent to Spam or rejected. This is no longer a security issue alone, it is a deliverability issue that hits your invoices, your newsletters and your support replies.
Google (Gmail)
Enforced February 2024Bulk senders to Gmail accounts must publish DMARC, align SPF or DKIM, and honour one-click unsubscribe. Mail that fails is rejected outright.
Yahoo Mail
Enforced February 2024Mirrors the Google sender requirements. Bulk and transactional mail without DMARC is throttled or sent to Junk.
Microsoft (Outlook)
Enforced May 2025Outlook.com, Hotmail and Live mailboxes now require SPF, DKIM and DMARC. Non-compliant bulk mail is routed to Junk or rejected.
Apple iCloud Mail
Enforced 2024 onwardsAligns with the Gmail and Yahoo sender rules. DMARC is treated as a precondition for inbox placement.
Sources: Google Email Sender Guidelines, Yahoo Sender Best Practices, Microsoft High Volume Sender Requirements, Sendmarc 2025 reporting.
DMARC policy states
"We have DMARC" is not the same as protected.
DMARC has three policy states. Only one of them actually stops impersonation. Most Australian domains we audit are stuck at the first.
Monitoring
DMARC record published. Reports flow in. Nothing is blocked yet.
Spoofed mail still lands in customer inboxes.
Quarantine
Failing mail is sent to Junk or Spam. Receivers treat it with suspicion but may still display it.
Partial protection. Some impersonation still reaches users.
Enforcement
Failing mail is dropped at the receiver. Your brand cannot be spoofed by external senders.
The only state the ACSC and ASD recognise as protected.
Indicative block rates based on real client outcomes once Sendmarc is tuned. Actual figures depend on the cleanliness of legitimate sending sources before enforcement.
Breach detection
If your credentials are already on the dark web, DMARC won't help.
Most Australian businesses have no visibility of stolen company data circulating on criminal marketplaces. Breached credentials are how attackers bypass MFA, take over executive mailboxes and launch the BEC fraud DMARC was designed to stop.
33B+
Personal credentials stolen and circulating, including email and login details.
42M
Records exposed through data breaches in a recent 12-month window.
Source: Sendmarc Breach Detection, aggregated industry datasets.
Add breach monitoringWhat we monitor
Hijacked credentials and personal info
Discover exposed passwords, email addresses and personal employee data leaked to the dark web before attackers weaponise them.
Device breaches
Monitor data stolen from compromised personal and corporate devices including keyloggers and info-stealer malware drops.
Service provider breaches
Surface third-party and supplier breaches that touch your data, so you can notify customers in line with the Notifiable Data Breaches scheme.
The sooner you know about compromised data, the faster you can rotate credentials, alert customers, and contain the damage.
Run Check Point Harmony Email & Collaboration on your tenant for 30 days. On us.
Microsoft 365 and Google Workspace filtering catches commodity spam. It does not catch AI-crafted invoice fraud, supplier impersonation or business email compromise. Harmony's ML stack reads the way the message is written, the relationships in your tenant, and the behaviour around the click. Run it for 30 days, see what it finds, then decide.
- Deployed by our engineers into your Microsoft 365 or Google Workspace tenant
- AI and ML threat analytics running over real production mail flow
- Daily detection summary plus a written findings report at the end of the trial
- No credit card, no auto-renewal, no obligation to continue past 30 days
What the trial covers
30 days, end to end
Deployment in week one. Full ML telemetry from day two. Findings report in week four.
Sits alongside Microsoft or Google
API-based, no MX changes, no mail flow disruption, no outage risk to back out of.
Real findings, not a demo
We hand you a written report of every message the existing stack missed during the trial window.
Reference
The detail for the people who want the detail.
Attacker playbooks, the Australian regulatory frame and our 90-day delivery process in one place. Tap a tab to drill in.
What attackers do with an unprotected domain
Eight ways your domain is monetised the moment it's left open.
These aren't hypothetical. Every one of these tactics is in active use against Australian SMBs right now, accelerated by generative AI and cheap deepfake tooling.
Fake invoices and payment redirects
Spoofed mail from finance@yourcompany asking suppliers to update bank details. The most common variant of business email compromise in Australia.
Executive impersonation
Mail that looks like the CEO or CFO asking a junior staff member for urgent gift cards, wire transfers or sensitive documents.
Customer phishing
Order confirmations, delivery notices and account alerts sent to your customers from your real domain. Damages your brand trust permanently.
Credential harvesting
Login portals styled to match your tenant, linked from emails that pass basic checks because your domain is wide open.
Voice cloning follow-ups
AI-generated voice calls from a 'staff member' or 'supplier' confirming the email request. The combo bypasses staff suspicion.
Deepfake video escalations
Short fake video calls from a 'manager' authorising payments. Now cheap enough to deploy against mid-market Australian businesses.
Synthetic supplier identities
Fabricated supplier personas built across email, LinkedIn and ABN lookups to insert themselves into procurement workflows.
Supply chain pivot
Once one supplier is spoofed successfully, attackers reuse the playbook across their entire customer list. You may be next.
FAQs
The questions we get on every audit.
Stop letting attackers send mail in your name.
Most domains we audit have at least one critical email authentication gap. Find out where you stand before an attacker does. Free audit, no obligation, results the same week.
Delivering email security Brisbane, email security Hobart and Tasmania, and across Australia.

Remote Support