What You Need to Know About Google's Move to Strict DMARC Implementation

Share Button

Starting in June 2016, any DMARC-capable receivers will be instructed by Google to reject any emails that do not properly authenticate.

Google’s adoption of DMARC is a huge step in right direction for global DMARC deployment and a mark of stability in DMARC in general. While Yahoo previously announced this same policy, having Google, as the largest email provider in the world, moving to "reject" is a huge endorsement.

What does this mean for financial services and other companies, looking to ensure they are not adversely affected by these changes? Based on our experience helping customers fully deploy DMARC on the sender side, combined with recommendations from BITS (The Financial Services Roundtable), here are the five steps we recommend, to make sure your organization is DMARC ready before these changes take place.

  1. Audit: Create an inventory of your organization’s email domains, email streams, and email types, including all domains actively sending email as well as inactive domains registered for defensive or brand protection purposes. Active domains can contain multiple email streams originating from different groups or vendors. DMARC-provided data and/or the Trusted Email Registry can augment in-house research and reduce the cost of discovering email streams.
  2. Detect: Compare and contrast real-world data against your stated email authentication implementation strategy.
  3. Remediate: Resolve any email authentication implementation issues or operational issues uncovered during the Audit or Detect phases.
  4. Secure: Implement blocking policies for both active and inactive domains. Publishing a blocking policy allows participating ISPs to either quarantine or reject unauthenticated email on your behalf.
  5. Monitor: Continue to look for new signs of abuse, operational issues, changes in network topology, and other anomalies. Aggressively pursue takedowns to gain a reputation for being a 'hard target'.

DMARC is a useful authentication standard, that will help reduce the amount of spam delivered worldwide. While many organizations have been dragging their feet on adoption, Google's move to a strict reject policy means that no company wanting to communicate with their clients can continue to ignore it.

To learn how we can help you automate DMARC processes, visit: http://www.easysol.net/products/easy-sol-solutions/dmarc-email-authentication.

Related Posts

Meet Lucifer: A New International Trojan The cat-and-mouse game between cybercriminals and security analysts never stops. Every so often, the mouse (in this case, represented by some kind of malware) pulls out front at a pace that catches that cat (the security solution) off guard.
Blunt Phishing’s Hook with Victim Insights 2.0

Typically, anti-phishing protection is a hammer that views every malicious site as a similarly-sized nail. It discovers a phishing site, slates it for removal, and eventually removes it from the...internet so that users can’t click on or enter their credentials into it.

Leave a Reply

Your email address will not be published. Required fields are marked *