EmailAuthKit

DMARC Rollout Case Study

This fictional rollout shows how evidence, not a calendar alone, governs movement from monitoring towards enforcement.

Starting state

A company inventories Workspace mail, a billing platform and a newsletter service, then publishes DMARC monitoring with aggregate reporting. It makes no inbox-placement promise.

First evidence

Workspace aligns through DKIM, billing aligns through SPF and the newsletter passes SPF for a provider domain but does not align. Unknown traffic is separated from confirmed business routes.

Correct the route

The newsletter provider's documented custom-domain signing is configured and tested with an independent recipient. Received headers and aggregate reports are both checked.

Bounded enforcement

After legitimate routes remain aligned, the company considers a limited quarantine percentage. The exact policy, percentage, date, owner and rollback value are recorded.

Exception handling

A forgotten support system appears in reports. Enforcement is not expanded until its ownership and replacement or alignment plan are decided.

Lesson

DMARC rollout is an operational process. Real senders, alignment evidence, change control and recipient expectations matter more than achieving a website score.

Authoritative references

Read the underlying standards and provider instructions before changing production DNS: RFC 7208 (SPF), RFC 9989 (DMARC), Google Workspace SPF guidance and your sending provider's current DKIM documentation.

Editorial responsibility

Published by Acerville Sparks Limited. Software assists research, drafting and automated record testing. Internet standards, provider documentation, reproducible checks and limitations are shown so readers can inspect the work. No independent deliverability consultant review is claimed. Reviewed 4 September 2026.

What this site does not do

No inbox guarantee. No live DNS checks. No storage of entered data. No passwords or private keys requested.