Red Sift OnDMARC for MSPs
Protecting email brands from impersonation by cybercriminals is essential. The burgeoning number of phishing and ransomware attacks we have seen over the last few years using email as an attack method shows this. The UK Cabinet Office (as early as 2016) and the USA Department for Homeland Security in 2018 identified protecting email domains as necessary. And things have only gotten worse since then.
The way that the UK and USA Governments stipulated that organisations should protect email was to use DMARC as part of an overall cybersecurity strategy. DMARC is an acronym for Domain Based Message Authentication, Reporting & Conformance. It is an open industry standard that allows mail servers in email sending and receiving organisations to coordinate and check that the sender using a domain name is authentic.
DMARC services are an essential part of any cybersecurity strategy. For service providers, they are an attractive and margin enhancing addition to a portfolio. Providing DMARC services for your clients doesn't mean building your own DMARC stack from scratch. Red Sift provides the industry-leading OnDMARC solutions, and they make it available to managed service providers (MSPs) to resell to their clients. Renaissance partner with Red Sift to make the OnDMARC solutions available to MSPs in Ireland. Give us a call today to find out more, and read on for an overview of DMARC and what Red Sift OnDMARC for Partners offers.
What is DMARC?
DMARC allows all email senders and receivers to verify that every email from a domain is really from whom the sender claims to be. It does this by augmenting DNS records with additional information that no one can spoof.
We won't go into the deep technical details of DMARC record checking here. See the Red Sift site for a deep dive. In summary, a DMARC policy solution works via a protocol called Sender Policy Framework (SPF) used to authenticate email senders, and the DKIM (DomainKeys Identified Mail) standard to sign emails digitally. These are then used between sending and recipient domains to verify the authenticity of incoming emails.
Any organisation and domain owner can adopt DMARC authentication to protect against email domain spoofing by cybercriminals. It is the only sure-fire way that email receivers know that the emails they receive come from the organisation whose domain is in the sender's address. DMARC uses email authentication and associated authentication methods to ensure that only legitimate email is delivered. DMARC adoption is an effective way for organisations to filter out fraudulent emails and reduce sender fraud and phishing attacks from unauthenticated emails.
Red Sift OnDMARC for Partners
Red Sift's OnDMARC is a global leader in the DMARC email domain protection space. It was recognised by Gartner for Brand Protection in their 2020 Market Guide for Email Security. The US Government also adopted Red Sift OnDMARC and used it to protect 150 separate government email domains in just two months. If it's good enough for the US Government, then it's likely to be good enough for your clients.
How Does OnDMARC Work for Service Providers?
OnDMARC is powerful while being simple to configure and deploy. Delivered via the cloud, it simplifies the automated setup of SPF, DKIM, and DMARC settings for all legitimate email sources. Real-world deployments show two-thirds of all OnDMARC deployments completed without the organisations in question having to consult the Red Sift support teams for help. They make it easy for MSPs to deploy protection for their clients without resource-intensive and expensive overheads. However, if assistance is required, the Red Sift support experts are always available to assist with setup or issues.
When deployed, OnDMARC provides the following protections:
Insight - See who is using your domain to send fake emails. Analyse and interpret the OnDMARC reports you receive to show what's going on across your email domains.
Action - Auto-classify legitimate senders and find the bad ones. Save time with automated classification and provide specific actions to secure genuine email sources and block the fake ones.
Protection - Stop cybercriminals sending fraudulent emails using your client's domain name. Once OnDMARC is fully deployed, it will continue to monitor for new email sources to protect against further attacks and ensure ongoing protection.
Some Benefits of OnDMARC to Convince your Clients
Many global businesses have seen the benefits that flow from implementing DMARC. Household names such as Netflix, Apple, DHL, Facebook, Citi, Twitter, UPS, and many others have implemented DMARC, which now protects billions of mailboxes worldwide. Government organisations such as the UK Government, NIST, and the Federal Trade Commission in the USA recommend that DMARC protects email domains from impersonation attacks.
When MSPs are discussing cybersecurity with their clients, they can use the following benefits of DMARC protection to convince them to adopt it and deploy Red Sift OnDMARC:
Brand Protection - it is a question of when, not if, a business email domain will be used for a cyberattack against other organisations. Whether it's phishing, malware distribution, or nuisance spam, the brand is harmed when perceived to be associated with these malicious emails.
Increased Email Deliverability - receiving email systems have powerful spam filters. They are often very aggressive in what they classify as spam. Implementing OnDMARC allows sending servers to inform receiving servers that the emails are legitimate. This reduces the likelihood that they will be classed as spam.
Reduced Service Calls - preventing the use of an email domain to cybercriminals minimises the number of support calls that result from suspicious emails your clients and business partners receive.
Visibility into Cyberattack Risk - OnDMARC allows you to see the volume of third parties sending emails from your domain. If they are cybercriminals using the domain, then you can take steps to prevent this use. If they are legitimate third-party services that are allowed to send emails on your behalf (such as a marketing partner), then OnDMARC will give you visibility to ensure they are complying with your email best practices.
Business email compromise (BEC) protection - most people have seen emails pretending to be from the CEO or CFO of an organisation or a business partner asking for confidential information. OnDMARC protects against this often used kind of cyberattack (known as spear-phishing).
DMARC needs to be part of a broader solution to protect against email domain name spoofing adequately. OnDMARC on its own will protect against Direct/Same Domain Spoofing. Businesses will need additional security to protect against Display Name Spoofing and Look-alike Domain Spoofing. In these latter cases, a character in an email address is changed to make it slightly different but very like a well-known legitimate brand. For example, by changing one character in the domain name such as the letter O to the number 0.
Find Out More
Email is still the number one business communication tool. Cybercriminals know this and attack it aggressively. Red Sift OnDMARC can protect against multiple email attack types that the bad guys use. It is easy to deploy and gives MSPs another solution they can resell to their clients while improving the security posture. Contact us to find out more.

