
Not sure whether your domain is protected against email spoofing? Check your DMARC score.
Managed DMARC protection for professional firms
ARMD.digital protects financial services providers, law firms, accountants and professional practices whose email carries payment instructions, client information or advice.
Where a domain can be spoofed, attackers can send convincing payment redirection and false instruction emails that appear to come from your firm.
Why DMARC matters in South Africa
Most cyber incidents still begin with email, and domain spoofing is one of the easiest routes in. Criminals borrow the trust of your domain to send emails that appear to come from you, without ever touching your systems.
In South Africa this often shows up as payment redirection: a message carrying changed banking details, apparently from a firm the recipient already knows. It’s why firms now add warnings to their email signatures telling clients that banking details will never change by email.
A signature warning asks the recipient to be careful. DMARC enforcement stops the email being delivered at all.
Email Spoofing:
The threat most security strategies miss
Most cybersecurity strategies focus on blocking threats that try to enter your systems, such as malware, unauthorised access, or suspicious links.
Email spoofing is different. It does not require attackers to break into your network. Instead, they misuse your domain identity to send emails that look legitimate to clients, suppliers, or staff.
That is why DMARC is so important. It helps receiving mail servers verify whether an email using your domain is authorised, and when enforcement is applied, reject messages that fail those checks.
DMARC closes a gap that many traditional security tools were never designed to address.

How ARMD.digital secures your domain with DMARC
Setup
We configure SPF, DKIM and DMARC so receiving mail servers can verify your approved senders and flag anything trying to misuse your domain. You don’t need to interpret any of it, and nothing changes for the people sending your email.
Monitoring
You get a clear picture of everything sending mail as your domain, authorised or not, in plain language rather than raw technical data. That’s usually the first time an organisation sees the full list.
p=reject Enforcement
Most domains reach p=reject within 90 days, the strongest DMARC policy setting. This instructs receiving mail servers to reject unauthorised emails that fail DMARC checks, significantly reducing the risk of direct domain spoofing.


Know your score
Check your domain’s protection in under 5 seconds.
Use our free DMARC Security Score Checker to see how well your domain is protected against email spoofing.
Enter your work email address – or simply type score@yourdomain if you’d prefer not to use a personal inbox – and we’ll assess your domain instantly.
You’ll see whether your domain is:
- High risk (score of 3 or less)
- Partially protected (score of 4)
- Fully protected (score of 5/5)
The DMARC detail that actually matters
Many businesses are told that simply “having DMARC” means their domain is protected. What’s often missed is that DMARC only works when it’s fully enforced.
At p=none you’re monitoring spoofing activity, not stopping it. At p=quarantine spoofed emails still reach spam folders, where they can be mistaken for legitimate messages. Only p=reject instructs receiving mail servers to refuse them outright.
Until a domain reaches p=reject, direct impersonation of that domain remains possible. That’s why ARMD.digital doesn’t stop at setup. We move your domain through monitoring and validation to full enforcement, and keep it there.
What happens when you get DMARC right

IT Consultancy Firm
The firm believed they had protected themselves by setting up DMARC independently.
On paper, everything looked correct.
But attackers still successfully spoofed their domain — not because anyone had compromised their systems, but because key platform-specific configurations were missing.
The problem only became clear when our specialist DMARC monitoring platform analysed the domain.
Our team then safely reconfigured the DMARC policy and moved it to full enforcement.
Today, continuous monitoring keeps the domain fully protected, with clear evidence that the system is blocking spoofed emails.
An Educational Institution
A private school had an ongoing problem: critical emails — including invoices and important parent communications — were landing in spam folders.
Initial attempts to fix the issue focused on email settings and content, but the root cause remained elusive.
Our specialist DMARC monitoring platform analysed the domain and identified the real culprit: incomplete email authentication tied to their DMARC configuration.
We correctly configured their DMARC policy and moved it to full enforcement, resolving the problem entirely.
Today, continuous monitoring keeps the school’s domain fully protected against spoofing, and legitimate emails reach parents, staff, and service providers reliably – without disruption.

Enforcement is what closes the gap attackers use
Email impersonation remains one of the most common tools attackers use against unprotected domains. Without full DMARC enforcement, that risk does not go away.
ARMD.digital moves your domain to full enforcement and keeps it monitored, so direct impersonation stops being an open route for attackers.
Ready to get started?
Generate your own quote online and continue straight to checkout from your emailed quote. No sales call, no waiting.
DMARC South Africa: FAQs on Protection, Enforcement and Support
Clear answers about managed DMARC protection in South Africa, including domain spoofing, DMARC enforcement, implementation timelines, managed support, and how to move safely towards p=reject.
Can someone send fake emails using my domain?
Yes. If your domain is not properly protected with SPF, DKIM and DMARC enforcement, attackers may be able to send emails that appear to come from your business. DMARC helps receiving mail servers verify whether emails using your domain are authorised, reducing the risk of spoofing, impersonation and Business Email Compromise.
Isn’t my antivirus and spam filter enough to protect against spoofed emails?
No. Antivirus and spam filters defend your internal systems against inbound threats.
Without DMARC enforcement, attackers can send fake emails that appear to come from your domain.
Does DMARC block all phishing attacks?
No single technology stops all phishing attacks.
DMARC protects your domain against attackers who impersonate it — a practice known as spoofing.
However, attackers can still create lookalike domains (like swapping letters) or use other tactics to trick users.
DMARC forms an essential part of a layered cybersecurity strategy, but works best alongside user awareness and additional threat detection tools.
What are the 3 stages of DMARC implementation?
Successful DMARC implementation happens in three clear stages, based on the ‘p=’ policy values:
- p=none – In this first phase, the system monitors emails but takes no action. All emails still process normally.
- p=quarantine – In this second phase, the system redirects unauthorised emails to spam or quarantine.
- p=reject – In this final phase, the system blocks unauthorised emails outright.
Your domain remains exposed to spoofing and impersonation until you set your DMARC policy to p=reject.
Is setting up DMARC enough to fully protect my domain?
No. A DMARC record at p=none offers monitoring, not protection.
Until your domain reaches p=reject, attackers can still impersonate your brand. Most businesses don’t realise that moving safely through p=none, p=quarantine, and p=reject is a specialist process — requiring real-time reporting, careful authentication alignment, and expert risk management to avoid blocking legitimate emails.
Even experienced IT teams often lack the tools and expertise for this journey. DMARC enforcement is a specialist cybersecurity function, not a standard IT task.
ARMD.digital guides your domain all the way to full p=reject enforcement — safely and with confidence.
How do I add the DMARC records at my DNS provider?
When you sign up, your onboarding email names your DNS provider and contains your exact records, together with a link to the matching step-by-step guide. You can also browse all our DNS setup guides to see how simple the process is, or to forward to whoever manages your domain.
What if I already have DMARC set up?
Many businesses have DMARC set to p=none or p=quarantine, which still leaves them vulnerable – and allows spoofed emails to slip through or land in junk folders.
Basic DMARC setups often generate confusing reports that offer little real-world value.
Our platform delivers clear, actionable reporting – making it easy to see what’s happening with your domain.
If you’re still sitting at p=none or p=quarantine, how long have you stayed there?
Without full enforcement, your domain remains exposed.
ARMD.digital moves your domain to full p=reject enforcement within 90 days, closing gaps and stopping threats with visible, trusted results.
If Microsoft 365 or Google Workspace support DMARC, why would I still need your services?
While Microsoft 365 and Google Workspace enforce DMARC policies within their own environments, they can only do so for emails sent through their systems.
But your business likely uses other tools – like CRM platforms, payroll systems, marketing tools, or website forms – that also send emails on your behalf.
Without full visibility and reporting, it’s easy to miss legitimate systems – or overlook unauthorised ones.
Also, it’s still your responsibility to correctly configure SPF, DKIM, and DMARC across all sources.
Microsoft and Google follow the authentication rules – but they don’t configure your domain for you.
ARMD.digital’s process properly aligns all your legitimate email sources, closing gaps, preventing delivery failures, and safely moving your domain to full protection.
Who provides DMARC support in South Africa?
ARMD.digital provides South African-based managed DMARC protection. The service helps organisations configure SPF, DKIM and DMARC, monitor authorised senders, and move safely towards enforcement.
How long does it take to get fully protected?
Our process moves your domain to full DMARC protection (p=reject) within 90 days.
This timeframe gives you enough time to configure all legitimate email sources correctly, so you don’t accidentally block valid communications.
It’s a balance of speed and safety to protect your brand and your deliverability at the same time.
Could implementing DMARC affect the legitimate emails my company sends?
Incorrect DMARC implementation can block legitimate emails or push them to spam.
That’s why our phased approach is critical – we monitor, adjust, and validate every source you use before moving you to enforcement.
Done properly, DMARC improves email deliverability.
Will DMARC help my email reach the inbox?
Correct SPF, DKIM and DMARC alignment is one of the signals receiving mail servers use when deciding where to place a message.
Properly authenticated mail is more likely to be treated as legitimate.
DMARC does not control inbox placement on its own, since content, sending history and recipient behaviour all matter, but poor authentication actively works against you.
What are the benefits of DMARC?
Implementing DMARC helps safeguard your reputation, increases email visibility, improves deliverability, and ensures compliance with major platforms like Google, Yahoo!, Microsoft, and frameworks like PCI-DSS.
It builds trust with clients, suppliers, and employees – and shows regulators and insurers that you take cybersecurity seriously.
How was DMARC developed?
Leading organisations and industry experts developed DMARC together, extending the existing email authentication protocols SPF and DKIM.
The concept was first developed in 2010 and officially published in 2012 to combat fraudulent email practices and improve deliverability.
Key contributors included companies like Microsoft, Google, Yahoo!, and PayPal – making DMARC a globally recognized standard for email security today.
Already setting up Managed DMARC Protection?
Use our DNS setup guides to add the records from your ARMD onboarding email.