← All resources
ArticleEmail security

DMARC for small business in BC: how to stop people sending email as you

Anyone can put your company's address in the From line of an email. SPF, DKIM and DMARC let you stop that without blocking your own mail.

Jake, Umbrella IT·September 16, 2026·5 min read

Anyone with a cheap mail server can send an email that shows accounts@yourcompany.ca in the From line and asks one of your clients to pay an invoice into a new bank account. Whether that fake reaches their inbox depends on a few DNS records on your domain, and setting up DMARC for small business domains like yours is how you get it blocked.

What we found in Lower Mainland domains

When we checked the public DNS records of 3,392 Lower Mainland businesses in September 2026, 52% had no DMARC record at all. Another 29% had DMARC set to monitor only (p=none), which asks for reports but tells other mail servers to deliver fake messages anyway. So about 81% of the accounting offices, law firms, dental clinics, trades companies and others we looked at had no DMARC protection being enforced. Only 12% were set to quarantine and 7% to reject, and 19% had no SPF record, the most basic of the three checks.

SPF, DKIM and DMARC for small business, in everyday words

SPF is a list, published in your domain’s DNS, of the mail services allowed to send email for you, such as Microsoft 365 and your newsletter tool. The receiving server checks whether a message came from a service on that list.

DKIM adds a digital signature to every message your mail service sends. The receiving server checks that signature against a public key in your DNS. If they match, the message came from a system holding your key and nobody changed it on the way.

Those two have a gap. Both check a behind-the-scenes address that the reader never sees, so a scammer can pass SPF and DKIM with their own domain while showing yours in the From line. DMARC closes that gap by requiring the domain that passed SPF or DKIM to match the From address the reader sees. It also tells receiving servers what to do with messages that fail, and it asks them to send you reports on who is sending mail using your name. The Canadian Centre for Cyber Security’s email domain protection guidance says you need all three working together for full protection.

What p=none, quarantine and reject mean

The policy is one setting in your DMARC record. p=none means deliver failing mail as normal and send me reports. p=quarantine means deliver it but mark it as suspicious, which often puts it in the junk folder. p=reject means refuse it. The Cyber Centre’s guidance is direct about this: none and quarantine help you gather information and set things up, but only reject applied to 100% of failing mail stops all of the fakes from being delivered.

Why so many businesses stop at monitor-only

Both the Cyber Centre and Microsoft say to start at p=none. Moving past it means someone has to read the reports and track down every service that sends mail as you. Those reports arrive as XML file attachments from several different mail providers, usually once a day, and they’re hard to read without a tool. So the record gets published and the reports pile up in a mailbox nobody opens, while the policy stays where it started. There’s a fair worry behind the hesitation too, because if you switch to reject before your accounting software is set up properly, your own invoices bounce.

A realistic rollout

Start by listing every system that sends email with your domain in the From line. For a six-person accounting office in Richmond, that’s usually the mailbox service (Microsoft 365 or Google Workspace), the accounting software that emails invoices and statements, a newsletter tool, and the contact form on the website. A clinic in New Westminster might add a booking system that sends appointment reminders.

Next, publish a DMARC record with p=none and a reporting address (the rua= part of the record). The Cyber Centre notes that reports should start arriving within 24 hours. Read them for 2 to 4 weeks, looking for your own legitimate senders that fail. The fix is usually adding that service to your SPF record, or turning on DKIM signing inside the service, which normally means publishing a DNS record the service gives you. Keep an eye on SPF’s limit of 10 DNS lookups, since every service you add uses some of them and going over the limit breaks the record.

When the reports show your real mail passing, move to p=quarantine. You can phase it in with the pct= setting (25%, then 50%, then 100%), as Microsoft’s DMARC setup guide describes. Give that a couple of weeks, then move to p=reject. Keep the reports coming after that, because every new tool someone signs up for is a new sender. If you own other domains that never send mail, like an old business name or the .com version of your .ca, the Cyber Centre recommends publishing a reject record on those too.

Gmail gives you another reason to get this right. Since February 2024, Google’s email sender guidelines have required anyone sending to Gmail accounts to use SPF or DKIM, and anyone sending more than 5,000 messages a day to Gmail to publish DMARC as well. Yahoo has the same DMARC rule for bulk senders. Mail that fails these checks can be marked as spam or rejected.

Check your own domain today

  1. Enter your domain (the part after the @) in the MXToolbox DMARC lookup.
  2. If it finds no record, you have no DMARC. If the record shows p=none, you’re monitor-only.
  3. Run the same domain through Check MX in the Google Admin Toolbox, which checks your mail records, including SPF and DMARC.
  4. Look at the rua= address in your DMARC record and find out who reads that mailbox, if anyone.
  5. Write down every tool that sends email as your business, including the ones a past employee or web designer set up.

If you’re not sure where your email is hosted, start with our post on Microsoft 365, Google Workspace or your web host for business email.

Umbrella IT has looked after email and security for Metro Vancouver businesses since opening in Burnaby in 2013. If you’d rather not read XML reports yourself, that work falls under our cybersecurity service, and it usually starts with checking how Microsoft 365 signs your outgoing mail.

Common questions

How long does it take to set up DMARC?

Publishing the first record takes a few minutes. Getting safely to reject usually takes 4 to 8 weeks, and most of that time goes into reading reports and fixing your own senders.

Will DMARC stop my own emails from being delivered?

Not at p=none, which only reports. At quarantine or reject it can, if a legitimate sender isn’t set up yet, so fix your senders first.

Does DMARC stop all phishing email?

No. It stops mail that fakes your exact domain, while lookalike domains (yourcompany-ca.com) and hacked real mailboxes get past it, so MFA and staff training still matter.

If you’d like someone to look up your records and tell you where your domain stands, book a free IT assessment.

Want this checked against your own setup?

Book a free IT assessment and a senior tech will review where your business stands, with no obligation.