Ok I admit it - I am a DMARC advocate, evangelist and all round believer in this standard.
Key takeaway - DMARC protocol is FREE and you can implement DMARC whilst you do a review for the best email cloud security/filtering platform - they are independent of each other.
Scenario - I'm at dinner with friends:
Across the 30 odd years I've been in IT - 3 keys concepts I truly believe in:
Specifically on email, organisations spend an enormous amount of resource to protect this space but in many cases fail miserably. Every time I read about a data breach, I quickly scan that organisation for an SPF or DMARC record only to find that I'm shocked at the lack of basic 101 email domain security. Yes, if your organisation doesn't have an SPF or DMARC record, eventually you will be scammed.
No need for expensive cloud based email security gateways ? - Obviously there's a caveat with that statement - using an analogy, firstly lock your doors and close your windows before looking to acquire a security guard to sit at your front door. In other words, implement the email service completely by creating an SPF , DKIM and DMARC records are part of that implementation. Subsequently, or in parallel, review services from providers such as Cisco, Mimecast, McAfee, Symantec etc for key features such as email AV filtering amongst others.
Below are important links for either Gmail for business or O365 subscribers.
Most if not all email filtering appliances or cloud services are DMARC compliant. In other words, if your organisation implements DMARC, you can leverage this protocol when you subscribe to an email filtering service and eventually REJECT fake emails that use your domain both
inbound towards your employees oroutbound towards your customers and vendors.
It's a simple process.
By Con Lokos