Blog article

25 Aug 20265 minutes read

SendmarcSendmarc

DMARC Audit Documentation: What Auditors Actually Require

Digital Dashboard With Charts And Graphs Floating Over A Dark Blue Cyber Background

DMARC audit overview:

  • A policy set to p=reject isn't audit evidence on its own
  • DMARC audit documentation must show what was enforced, when, and by whom
  • Four things matter: DNS history, logs, reports, monitoring
  • Assign evidence collection to named roles, not teams
  1. Current DNS record (full TXT record value with timestamp of export)
  2. Change log with dates, prior values, new values, and approver identity
  3. Change request or ticket references
  • Volume of messages evaluated against your DMARC policy per reporting period
  • Volume and percentage of messages that failed authentication
  • Policy applied (p=none, p=quarantine, p=reject)
  • Source IP addresses of failing senders
  • Timestamps of reporting periods
  1. Total messages evaluated
  2. Disposition breakdown (passed, quarantined, rejected)
  3. Notable changes in sending source behavior during the period
  • Regular review of aggregate DMARC reports (monthly is a common minimum)
  • Documented responses to anomalies (new unauthorized senders, SPF failures from legitimate sources)
  • Change management records for any policy adjustments during the period
  • Alerts or tickets generated by monitoring tools when authentication failures exceeded defined thresholds
  • Export current DNS record and maintain a change log
  • Collect and archive aggregate DMARC reports monthly
  • Validate SPF and DKIM configuration on each sending domain at least quarterly
  • Document any new sending sources added during the DMARC audit period
  • Approve and document policy changes
  • Prepare the executive summary covering DMARC enforcement status
  • Map DMARC enforcement controls to specific framework requirements
  • Confirm that control descriptions in the risk register match the actual technical configuration
  • Review the evidence for completeness before submission to auditors

Share

Get our latest blogs delivered to your inbox each month

Leave a reply

Your email address will not be published. Required fields are marked *

Useful Tools

DNS Lookup
Free toolNo sign-up

DNS Lookup

Use Sendmarc's DNS lookup tool to instantly analyze domain records, verify configurations, and detect DNS issues for better performance.

Email Header Analyzer
Free toolNo sign-up

Email Header Analyzer

Quickly analyze email headers with Sendmarc’s email header analyzer. Check SPF, DKIM, and DMARC results, detect phishing, and improve email deliverability.

Domain Checker
Free toolNo sign-up

Domain Checker

Use the Sendmarc domain checker to test against malicious use - free, no sign-up required, with results in under a minute.