How to Add DMARC for Irish Business — 5-Minute Setup

Add DMARC to your Irish business email in 5 minutes — Microsoft 365, Google Workspace, or any DNS provider. Free, no software, stops spoofing today.

How to Add DMARC for Irish Business — 5-Minute Setup

Microsoft 365 Users: One Extra Step

If you use Microsoft 365 for your business email, enable DMARC reporting in the Microsoft Defender portal once your record is live. Go to security.microsoft.com, navigate to Email and Collaboration, then Policies and Rules, then Threat Policies, then Email Authentication Settings, and select the DMARC tab. This shows you whether your record is detected and in enforcement mode. While you are there, check the DKIM tab and enable DKIM signing for your domain if it is not already active — DMARC enforcement relies on DKIM being correctly configured.

Google Workspace Users: Check DKIM First

For Google Workspace, verify that DKIM is active before enabling DMARC enforcement. Go to admin.google.com, navigate to Apps, then Google Workspace, then Gmail, then Authenticate Email. Select your domain. If a DKIM key has been generated but not yet published in DNS, copy the TXT record value and add it to your DNS as a TXT record with the name google._domainkey.yourdomain.ie. Once DKIM is active and sending correctly, your DMARC quarantine policy will begin enforcing.

Reading Your DMARC Reports

Once your DMARC record is live, you will start receiving aggregate reports from major email providers — Google, Microsoft, Yahoo — at the address you specified in the rua= field. These reports arrive as XML files and show every mail server that sent email claiming to be from your domain, and whether those emails passed authentication checks. This information is genuinely useful: it tells you whether your legitimate email is correctly authenticated and flags any servers attempting to impersonate your domain.

Reading raw XML is impractical. Free tools such as DMARC Analyser and Postmark's DMARC Monitoring Tool parse the reports into readable summaries. Use one of these for the two to four weeks before you move to a reject policy.

Moving to Reject Policy

After two to four weeks of monitoring your reports and confirming that all legitimate email is passing authentication, change p=quarantine to p=reject in your DMARC record. With reject policy active, receiving servers will block any email that fails DMARC authentication outright — it will not even reach a spam folder. This is the strongest protection against email impersonation and the setting recommended by NCSC Ireland for organisations that have confirmed their legitimate email is correctly authenticated.[^2]

The Data Protection Commission considers email security controls a relevant factor in assessing whether an organisation has taken appropriate technical measures to protect personal data under GDPR Article 32. An organisation whose domain is actively being used to defraud its clients or suppliers without DMARC protection in place faces a difficult argument that it has met its data security obligations.[^3]

What Next: Three Actions

First, check whether DMARC exists on your domain today by searching _dmarc.yourdomain.ie at mxtoolbox.com. If no record is returned, your domain is currently unprotected and any criminal can impersonate your email. Fix this today — five minutes, no cost.

Second, add the DMARC record at quarantine level and set a calendar reminder for four weeks from today to review the aggregate reports and upgrade to reject. This two-stage approach protects you immediately while giving you visibility into your email authentication before you enable the strictest enforcement.

Third, verify that SPF and DKIM are correctly configured at the same time. A DMARC policy can only enforce against failures in SPF and DKIM alignment — if either is missing or misconfigured, your DMARC record cannot function correctly. Run a full email authentication check using MXToolbox or your email provider's security dashboard.

[^1]: NCSC Ireland — Advice for Organisations [^2]: An Garda Síochána — Cybercrime [^3]: Data Protection Commission Ireland

Related Reading