ActiScan
← DMARC Enforcement for MSPs

Final quiz

10 questions, 80% to pass. Your name and email are only used to issue your certificate – no password, no account.

1. Why is jumping straight from p=none to p=reject risky?
2. What does the `pct=` tag in a DMARC record actually control?
3. What's a real, meaningful signal that a domain is ready to escalate DMARC enforcement further?
4. Why might DKIM alignment scale better than SPF includes for a client with many sending vendors?
5. Why does a forwarded message typically fail SPF but can still pass DMARC?
6. What threat does MTA-STS specifically protect against?
7. What does TLS-RPT report on, distinct from a DMARC aggregate report?
8. Why does DNSSEC matter for every other check covered in this course?
9. Why is an unvalidated TLSA record not a real security guarantee?
10. What's the recommended first step when diagnosing a stalled DMARC rollout?