Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Email authentication
Reference · Pattern

SPF configured without DMARC alignment

Severity HighKind Email authenticationEffort to fix TrivialUpdated 29 Sep 2026By LeakTrace
Definition

A domain publishes an SPF record but no DMARC policy, leaving receivers with no instruction on how to handle unauthenticated mail.

What it is

SPF (Sender Policy Framework) tells receiving mail servers which IPs are allowed to send mail for a domain. DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells those receivers what to do when mail fails SPF or DKIM alignment, reject, quarantine, or monitor. Publishing SPF without DMARC is the equivalent of installing a burglar alarm and never turning it on.

Why it matters

Attackers targeting a firm for business email compromise (BEC) or wire-fraud pretext will test the domain's DMARC policy before staging the impersonation. A missing or permissive DMARC policy (p=none, or no record at all) means spoofed mail from the domain is likely to reach the inbox without a warning label.

How anyone can check it

nslookup -type=txt _dmarc.yourfirm.ca

If nothing comes back, there is no policy. If it says p=none, forged mail is still delivered.

Remediation direction

Publishing a DMARC record at _dmarc.<domain> with p=quarantine (or p=reject once legitimate sending is verified) closes the exposure. Start in monitor mode (p=none with rua= reporting) for two weeks to catalog every legitimate sender, then escalate the policy. Institutional-grade programs pair DMARC with DKIM signing on every legitimate sending path (marketing platform, ticketing system, ATS, e-sign vendor, etc.).

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →