Skip to content
arrow_back
search
ISM-1540 policy ASD Information Security Manual (ISM)

Configuring DMARC for Email Security

Ensure emails from your domains are legitimate by rejecting ones that fail DMARC checks.

record_voice_over

Plain language

Configuring DMARC for your organisation's emails ensures that only legitimate emails from your domain reach other people's inboxes. This is important because if unverified or fake emails aren't stopped, they could damage your reputation, expose your customers to scams, and result in financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

DMARC records are configured for an organisation's domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.
policy ASD Information Security Manual (ISM) ISM-1540
priority_high

Why it matters

If DMARC is not enforced, spoofed emails can bypass checks, enabling phishing, reputational harm and financial loss.

settings

Operational notes

Review DMARC aggregate reports, validate SPF/DKIM alignment, and tighten policy to quarantine/reject for all subdomains.

Mapping detail

Mapping

Direction

Controls