Ready to start?

We are here to help.

Microsoft is beginning the process of rejecting emails sent from high-volume senders

that do not comply with the DMARC policy, including SPF and DKIM checks when there is no full alignment.

The move aligns with a broader trend among email providers to tighten authentication requirements for large senders.

Relevant image

If an organization fails to meet the requirements, it faces several key risks:

  • Emails may be rejected or end up in Spam, significantly damaging the ability to communicate with customers and partners.
  • A sharp decline in the delivery rates of marketing, operational, and support emails.
  • It is easier for attackers to send emails spoofing the domain against recipients who do not perform strict authentication.
  • Damage to brand trust and increased exposure to business and regulatory risks.

What should we do now?

  • Make sure all domains are configured correctly with SPF, DKIM, and DMARC.
  • Move to a strict DMARC policy (quarantine / reject) and do not stay on none.
  • Check for full alignment between the From domain and the authentication domain.
  • Scan and identify any third-party service that sends emails on behalf of the company and ensure it is properly configured.
  • Monitor DMARC reports to understand who is sending and what the alignment level is.

How does IRONSCALES help?

Even with proper DMARC configurations, spoofing and BEC attacks bypass standard authentication using techniques such as Executive Impersonation, Vendor Fraud, and Lookalike Domains.

IRONSCALES provides an AI-based and identity-biased detection defense layer that protects against behavioral-based impersonation, not just protocols.

For a more detailed explanation, send an email to our sales team:

[email protected]

More articles

Do you have any more questions?

Leave your details and a representative will contact you with more information.

ֿ
For consultation

Leave your details and we will contact you soon.