International DMARC mandates & email security regulations


Government

Regulation: Canadian government email policy

Region: Canada

What it means: Government emails must implement SPF, DKIM, and a DMARC policy of p=quarantine or p=reject.

Mandated for DMARC: Yes

Regulation: BODBinding Operational Directive 18-01

Region: United States

What it means: Federal agencies must enforce STARTTLS, SPF, DKIM, and DMARC with a p=reject policy.

Mandated for DMARC: Yes

Regulation: California SIMMCalifornia Statewide Information Management Manual – 5315A

Region: United States (California)

What it means: State agencies must implement DMARC for email threat protection.

Mandated for DMARC: Yes

Regulation: MS-ISACMulti-State Information Sharing and Analysis Center

Region: United States

What it means: Configure DMARC, SPF, and DKIM to enhance cybersecurity.

Mandated for DMARC: No

Regulation: Denmark government mandate

Region: Denmark

What it means: All government agencies must implement a DMARC policy of p=reject.

Mandated for DMARC: Yes

Regulation: Ireland public sector cybersecurity standard

Region: Ireland

What it means: Public service bodies should enforce SPF, DKIM, and DMARC.

Mandated for DMARC: No

Regulation: Netherlands government mandate

Region: Netherlands

What it means: Government agencies must implement STARTTLS, DANE, SPF, DKIM, and DMARC.

Mandated for DMARC: Yes

Regulation: UK government secure email policy

Region: United Kingdom

What it means: Government departments must implement TLS, DMARC, DKIM, and SPF.

Mandated for DMARC: Yes

Regulation: India government email security guidance

Region: India

What it means: Implement SPF, DKIM, and DMARC for enhanced email security.

Mandated for DMARC: No

Regulation: NZISMNew Zealand Information Security Manual v3.8

Region: New Zealand

What it means: Government agencies must use DMARC with a policy of p=reject, SPF, and DKIM.

Mandated for DMARC: Yes

Regulation: SGENew Zealand Secure Government Email framework

Region: New Zealand

What it means: All government organizations must adopt DMARC, SPF, DKIM, MTA-STS, and TLS-RPT.

Mandated for DMARC: Yes

Regulation: Cyber Essentials mark

Region: Singapore

What it means: Organizations must have SPF, DKIM, and DMARC in place.

Mandated for DMARC: Yes

Regulation: Rwanda financial sector mandate

Region: Rwanda

What it means: Financial institutions must implement SPF, DKIM, and DMARC.

Mandated for DMARC: Yes

Regulation: Rwanda public sector email security standard

Region: Rwanda

What it means: Public institutions should implement DMARC to block email impersonation.

Mandated for DMARC: No


Regulators and compliance

Regulation: CCPACalifornia Consumer Privacy Act

Region: United States (California)

What it means: Enforces customer data protection; DMARC helps secure sensitive information.

Mandated for DMARC: No

Regulation: CISCenter for Internet Security critical security controls

Region: United States

What it means: Implement DMARC to reduce successful email spoofing attacks.

Mandated for DMARC: No

Regulation: FedRAMPFederal Risk and Authorization Management Program DMARC

Region: United States

What it means: Cloud service providers must enforce a p=reject DMARC policy.

Mandated for DMARC: Yes

Regulation: CMMCCybersecurity Maturity Model Certification

Region: United States

What it means: Businesses working with the Department of Defense (DoD) must protect sensitive information. DMARC improves security, reducing the risk of information leaks.

Mandated for DMARC: No

Regulation: NIST CSFNational Institute of Standards and Technology Cybersecurity Framework

Region: United States

What it means: Organizations should reduce cybersecurity risks by implementing solutions such as DMARC.

Mandated for DMARC: No

Regulation: GDPRGeneral Data Protection Regulation

Region: European Union

What it means: Requires businesses to protect personal data. By safeguarding email data from unauthorized access, DMARC helps with GDPR compliance.

Mandated for DMARC: No

Regulation: France email security guidance

Region: France

What it means: Email administrators should implement SPF, DKIM, and DMARC.

Mandated for DMARC: No

Regulation: Germany ISP security guidance

Region: Germany

What it means: ISPs should use DMARC, SPF, and DKIM to combat Spam and phishing.

Mandated for DMARC: No

Regulation: Portugal cybersecurity recommendations

Region: Portugal

What it means: Organizations should implement DMARC for active and parked domains.

Mandated for DMARC: No

Regulation: Scotland cyber resilience action plan

Region: Scotland

What it means: Public sector organizations should implement cybersecurity measures like DMARC.

Mandated for DMARC: No

Regulation: UK public sector email security

Region: United Kingdom

What it means: Public sector emails must use TLS and DMARC to encrypt and authenticate email.

Mandated for DMARC: Yes

Regulation: Australia cybersecurity guidelines

Region: Australia

What it means: Configure SPF, DKIM, and DMARC with a p=reject policy to reduce email threats.

Mandated for DMARC: No

Regulation: ECCSaudi Arabia Essential Cybersecurity Controls

Region: Saudi Arabia

What it means: Organizations must implement strong email protection, including SPF, DKIM, and DMARC.

Mandated for DMARC: Yes

Regulation: POPIAProtection of Personal Information Act

Region: South Africa

What it means: Take reasonable measures to prevent unauthorized access to personal information. DMARC can enhance the protection of sensitive data.

Mandated for DMARC: No

Regulation: Google & Yahoo bulk sender requirements

Region: International

What it means: Organizations sending over 5 000 emails a day must authenticate domains with TLS, DKIM, SPF, and a DMARC policy of p=none at minimum.

Mandated for DMARC: Yes

Regulation: Microsoft high-volume sender requirements

Region: International

What it means: Businesses that send over 5 000 emails per day to Microsoft domains must implement SPF, DKIM, and a DMARC policy of at least p=none.

Mandated for DMARC: Yes

Regulation: Cloudflare Email Routing

Region: International

What it means: Sending domains must pass either SPF or DKIM checks. DMARC is strongly recommended.

Mandated for DMARC: No

Regulation: ISO/IECInternational Organization for Standardization / International Electrotechnical Commission 27001

Region: International

What it means: Organizations must manage information security risks effectively for ISO/IEC 27001 compliance. Implementing DMARC can help companies comply.

Mandated for DMARC: No

Regulation: SMB1001

Region: International

What it means: Businesses must have SPF and DKIM in place and enforce DMARC with a policy of p=quarantine or p=reject.

Mandated for DMARC: Yes


Financial

Regulation: PCI DSSPayment Card Industry Data Security Standard v4.0

Region: International

What it means: Requires automated mechanisms to detect and protect against phishing. DMARC, SPF, and DKIM are recommended best practices.

Mandated for DMARC: No

Regulation: GLBAPrivacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act

Region: United States

What it means: Requires financial institutions to protect customer data; DMARC can help enhance defenses.

Mandated for DMARC: No


Healthcare

Regulation: UK NHS email security policy

Region: United Kingdom

What it means: NHS-accredited organizations must implement an email service that supports DMARC.

Mandated for DMARC: Yes

Regulation: HIPAAHealth Insurance Portability and Accountability Act

Region: United States

What it means: Ensures privacy and security of patient data; DMARC can increase protection by reducing successful phishing attempts.

Mandated for DMARC: No


Why DMARC matters


Want to learn more about DMARC mandates?

We’ve released a blog on everything Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) should know about DMARC global mandates.

Read now