Blog article

15 Sep 20266 minutes read

SendmarcSendmarc

Domain Audit Workflows: From Compliance Review to Governance

Illustration of a systematic domain audit workflow tracking DMARC, SPF, and DKIM posture across a domain portfolio

Domain audit overview:

  • Reactive, one-off checks don't build a baseline, a repeatable process, or an audit trail.
  • Compliance reviews require documented proof that a policy was verified on a specific date.
  • Without a pre-incident baseline, incident response has nothing to compare against.
  • Governing multiple domains requires visibility across the entire portfolio.
  1. Pull the domain inventory from your authoritative source: your DNS management platform, asset register, or DMARC reporting dashboard. Include all active sending domains, parked domains, and subsidiary domains acquired through M&A.
  2. Run a domain check against each entry. Capture the full output: DMARC policy, SPF include depth, DKIM selector presence.
  3. Store the output with a timestamp and reviewer identity, and log it in your GRC platform or risk register. That entry becomes part of the domain's audit trail.
  4. Flag any domain that doesn't match what you'd expect to see, such as an SPF record that has grown past the 10-lookup limit, or a DKIM record still authorizing a sender that's no longer in use.
  5. Assign remediation owners with a deadline before the next compliance review cycle.
  1. Run an immediate domain check on the affected domain and any lookalike domains identified in the alert. This gives you the current state, independent of whether a scheduled review has run recently.
  2. Confirm whether the current SPF/DKIM/DMARC configuration matches what's expected for that domain.
  3. If DMARC is at or , treat that as a possible cause: it means spoofed email isn't being blocked. Evaluate emergency escalation to .
  4. Document every finding and action with a timestamp for post-incident review.
  1. Maintain a single authoritative domain inventory. Every domain the business owns should appear here, categorized by risk tier (active sending, parked, subsidiary).
  2. Assign a policy baseline to each tier. Active sending domains target . Parked domains that don't send email should also have a . They are a common spoofing vector precisely because they're often overlooked.
  3. Set up continuous monitoring for every domain in the inventory. A multi-tenant platform that automates this reduces manual overhead and produces credible reporting.
  4. Review the output for policy consistency. A domain that drops to without a documented change request represents an unauthorized configuration change.
  5. Generate a summary that maps each domain to its current policy, last update, and any open findings.

Share

Get our latest blogs delivered to your inbox each month

Leave a reply

Your email address will not be published. Required fields are marked *

Useful Tools

DNS Lookup
Free toolNo sign-up

DNS Lookup

Use Sendmarc's DNS lookup tool to instantly analyze domain records, verify configurations, and detect DNS issues for better performance.

Email Header Analyzer
Free toolNo sign-up

Email Header Analyzer

Quickly analyze email headers with Sendmarc’s email header analyzer. Check SPF, DKIM, and DMARC results, detect phishing, and improve email deliverability.

Domain Checker
Free toolNo sign-up

Domain Checker

Use the Sendmarc domain checker to test against malicious use - free, no sign-up required, with results in under a minute.