Skip to content
arrow_back
search
ISM-1799 policy ASD Information Security Manual (ISM)

Enforce Email Rejection for Failed DMARC Checks

Emails not verified by DMARC are blocked to enhance email security.

record_voice_over

Plain language

This control makes sure that emails failing to verify through DMARC checks are blocked. It's important because it keeps potentially dangerous or fraudulent emails out of your inbox, protecting your business from phishing attacks or scams that could lead to data loss or financial harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Incoming emails are rejected if they do not pass DMARC checks.
policy ASD Information Security Manual (ISM) ISM-1799
priority_high

Why it matters

If emails that fail DMARC are not rejected, spoofed messages can reach users, increasing phishing and the likelihood of credential theft or fraud.

settings

Operational notes

Review DMARC aggregate reports and adjust SPF/DKIM alignment so valid senders pass; keep the DMARC policy at reject to block spoofed mail.

Mapping detail

Mapping

Direction

Controls