Skip to content
VetThisVendor

No DMARC policy found

If the sending-domain check reported no enforced DMARC policy, it means anyone on the internet can send email that appears to come from that domain, and receiving mail servers have not been told to reject it.

Why this sits next to a VAT check

Most invoice fraud does not involve a fake company. It involves a real supplier, a real invoice, and changed bank details — delivered by an email that appears to come from the supplier’s own domain.

That email is convincing precisely because the domain is genuine. A registry check will pass. The company exists, the VAT number is valid, the trading relationship is real. The only thing wrong is the account number, and the only technical signal available in advance is whether that domain could have been forged in the first place.

The three records, and what each does

Without DMARC, a forged message that fails SPF may still land in the inbox.

Reading the policy

Policy What receivers do What it means for you
p=reject Forged mail is refused outright Strongest. Forgery is largely prevented
p=quarantine Forged mail goes to spam Good. Forgery usually does not reach the inbox
p=none Nothing — the domain only collects reports No protection. Monitoring mode only
no record Nothing No protection

p=none is the one that catches people out. The domain has a DMARC record, so a superficial check reports “DMARC: yes”, but it instructs receivers to do nothing at all. This tool reports it as unenforced, because that is what it is.

What to do

If this is your supplier: treat any request to change bank details from this domain with particular caution. Do not reply to the email to confirm — if the mailbox is compromised, or the message was forged, you are confirming with the fraudster. Phone a number you already had.

If this is your own domain: you can fix it. Publish SPF and DKIM, then add a DMARC record starting at p=none to collect reports, and move to p=quarantine and then p=reject once those reports show your legitimate mail passing. The sibling tool at notspoofed.com walks through exactly this and generates the records for you.

What it does not tell you

An enforced DMARC policy means the domain is hard to forge. It does not mean the mailbox was not compromised — an attacker sending from inside a real account passes every one of these checks. Confirming bank details by phone remains the control that catches it.

Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.