DMARC
Domain-based Message Authentication, Reporting, and Conformance
An email authentication protocol that tells receiving mail servers what to do with messages that fail sender authentication (SPF or DKIM).
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a DNS-published email policy that instructs receiving mail servers how to handle mail claiming to be from a domain but failing SPF or DKIM alignment. Policies range from monitoring only (p=none) through quarantine (p=quarantine) to rejection (p=reject). Domains without DMARC, or with DMARC set to p=none, are effectively spoofable at scale — attackers send email that appears to originate from the domain and receiving servers deliver it because there is no policy instructing them to reject unauthenticated mail. DMARC is standardized in RFC 7489. Auditing DMARC posture across an advisor tenant network is a wire-fraud precursor signal LeakTrace monitors continuously.
Family offices, wealth manager firms, and sports agencies typically hold sensitive wire instructions on advisor tenant infrastructure (CPA, attorney, wealth manager). A weak or missing DMARC policy on any of those advisor domains means an attacker can impersonate that advisor to the principal or counterparty, routing a wire instruction to a fraudulent account. DMARC posture is one of the first signals LeakTrace surfaces on the advisor tenant network.