ActiScan

DMARC

DMARC Just Became Internet Law — And That Changes the Math for Every MSP

September 19, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Laptop showing DNS and email authentication records on a dim desk beside undeliverable mail envelopes

For most of its existence, DMARC lived in the same bucket as backup testing and password rotation policies: a widely recommended practice that most organizations quietly skipped. That bucket no longer exists. Between February 2024 and May 2025, three of the world's largest mailbox providers and one of the most consequential compliance frameworks in commerce all converged on the same requirement, and the result is that DMARC has effectively become a condition of doing business by email.

Is DMARC now mandatory? For any organization sending meaningful volumes of email to Gmail, Yahoo, or Outlook.com addresses, or handling payment card data, yes in practical terms. Google, Yahoo, and Microsoft now reject or junk unauthenticated bulk mail outright, and PCI DSS 4.0 has made anti-phishing controls a certification requirement. Ignoring DMARC no longer just risks reputation. It risks delivery.

Why Did Email Providers Suddenly Make DMARC Non-Negotiable?

Because spoofed and unauthenticated mail had become the primary delivery mechanism for phishing and business email compromise, and self-policing had failed. Google and Yahoo announced in October 2023 that starting in February 2024 they would require any sender pushing more than 5,000 messages a day to Gmail addresses to authenticate with SPF and DKIM and to publish a DMARC record, with alignment against at least one of those two protocols. Microsoft followed on a slightly longer runway, confirming that as of May 5, 2025, Outlook would begin routing non-compliant high-volume mail to the Junk folder rather than the inbox, a move it framed as raising the bar for large senders to inspire lasting change that benefits everyone.

None of this happened in isolation. The three providers had watched the same abuse patterns for years and reached the same conclusion independently: unauthenticated mail was no longer worth the risk of delivering. Once one major provider drew the line, the others had every incentive to follow, since senders who cleaned up their authentication for Gmail had already done most of the work needed for Outlook and Yahoo Mail.

What Do the New Rules Actually Require, and Who Do They Cover?

The baseline is the same everywhere: a published DMARC record, SPF and DKIM in place, and alignment between the visible From domain and at least one authentication mechanism. Google's threshold for bulk sender status is any account sending close to 5,000 messages or more to personal Gmail addresses within a 24-hour period, a bar that a surprising number of small and midsize businesses cross without realizing it, especially during seasonal campaigns or mass client communications.

Microsoft's version applies the same 5,000-message threshold to Outlook.com, Hotmail.com, and Live.com traffic, and its own documentation is explicit that after the enforcement date, Outlook will begin routing messages from high-volume non-compliant domains to the Junk folder. None of the three major providers currently require a policy stricter than p=none for baseline compliance, which is the part MSPs need to internalize: publishing a do-nothing DMARC record technically satisfies the mailbox providers while leaving the client's domain wide open to spoofing, because p=none takes no enforcement action at all.

The compliance layer runs on a separate but overlapping track. PCI DSS 4.0's Requirement 5.4.1 mandated automated anti-phishing mechanisms as of March 31, 2025, and industry guidance has been direct that this requirement is not satisfied by security awareness training alone, pointing assessors toward SPF, DKIM, and DMARC as the practical controls. Federal agencies have lived under a stricter version of this rule since 2017, when DHS's Binding Operational Directive 18-01 required agencies to move to a DMARC policy of p=reject for all second-level domains and mail-sending hosts within a year of issuance, a full enforcement posture that the consumer mailbox providers still have not mandated eight years later.

The table below lines up the four tracks MSPs are now juggling on behalf of clients.

RequirementWho it coversMinimum barEffective date
Google bulk sender rules5,000+ msgs/day to GmailDMARC p=none, SPF/DKIM alignedFebruary 2024
Yahoo bulk sender rulesHigh-volume senders to Yahoo/AOLDMARC p=none, SPF/DKIM alignedFebruary 2024
Microsoft high-volume rules5,000+ msgs/day to Outlook.comDMARC p=none, SPF/DKIM alignedMay 2025
PCI DSS 4.0 Req. 5.4.1Cardholder data handlersAutomated anti-phishing controlsMarch 2025

How Does This Change the Math for MSPs?

It converts DMARC from an occasional client favor into recurring, billable, operationally necessary work. The addressable gap is still enormous: independent adoption research cited in Red Sift's MSP guidance found that fewer than one in twenty domains enforce a strict DMARC policy, meaning the vast majority of client domains are either unprotected or sitting at p=none, which is functionally the same thing from a spoofing standpoint.

That gap is not a technical afterthought for clients anymore. A client who ignores authentication now risks marketing sends bouncing, invoices landing in spam, and renewal notices never reaching customers, all before anyone even talks about phishing. An MSP that can walk a client from an unprotected domain to a monitored, aligned, enforced DMARC posture is solving a problem the client's own IT staff usually cannot diagnose on their own, because DMARC failures show up as vague deliverability complaints rather than obvious security incidents.

The complexity is real, though, and it is the reason this work resists a set-and-forget approach. Moving a domain from p=none to p=reject without breaking legitimate mail requires identifying every sending source, a step that becomes genuinely difficult once marketing platforms, help desk tools, and cloud services are all sending on the client's behalf using their own infrastructure.

What Should MSPs Actually Do First?

Start with discovery, not policy. Before any client domain touches p=quarantine or p=reject, someone has to build a full inventory of what is actually sending mail as that domain, because a strict policy published too early breaks legitimate traffic and generates support tickets that erode client trust in the whole initiative.

A practical rollout sequence looks like this:

  • Publish a DMARC record at p=none with aggregate reporting enabled, and let two to four weeks of reports establish a baseline of every sending source.
  • Reconcile each source against SPF and DKIM, flagging anything that fails alignment, including marketing platforms and SaaS tools sending on the client's behalf.
  • Move to p=quarantine once the known-good senders are all aligned, watching reports closely for anything unexpected.
  • Graduate to p=reject only after a sustained period with no legitimate mail failing, which is the posture that actually stops spoofing rather than just monitoring for it.

This is exactly the kind of repeatable, ticket-generating work that turns into a managed service line rather than a one-time project. ActiScan's own getting-started guide walks through the discovery and monitoring phase in more detail, since that is where most engagements either build client confidence or lose it. For MSPs weighing how this fits into existing service tiers, the pricing page breaks down how domain monitoring scales across a client book of any size, and the fastest way to see the reporting in action on a real domain is to go through sign-up directly.

The Bigger Shift Underneath the Deadlines

None of this is really about a single deadline. It is about the fact that the three companies that route most of the world's consumer email traffic, plus the body that certifies payment security, and a federal directive that has been in force since 2017, all now treat authentication as baseline hygiene rather than an advanced practice. That convergence is what makes the "internet law" framing fair even though no single legislature passed it.

For MSPs, the practical takeaway is not that every client is suddenly in violation of something. It is that the excuse for leaving domains unauthenticated has quietly disappeared, and the clients least likely to have noticed are precisely the ones who will feel it first the next time a mailbox provider tightens enforcement again. Building the monitoring and alignment workflow now, while it is still a proactive sell rather than a reactive fire drill, is the difference between capturing that market and reacting to it.

← Back to all posts