Scanning domains with DMARC p=none that lack active monitoring
Email spoofing remains a persistent threat to Australian organisations, from small e-commerce shops in Brisbane to large financial institutions in Sydney. A domain that publishes a DMARC record with p=none is essentially announcing that it will accept any email claiming to be from its domain, without instructing receiving servers to reject or quarantine fraudulent messages. This permissive posture is the most common starting point for organisations rolling out email authentication, yet it becomes dangerous when left in place indefinitely. Without active monitoring, a domain owner has no visibility into who is sending mail on their behalf or how often spoofing attempts occur.
The risk is not purely theoretical. The Australian Cyber Security Centre regularly flags business email compromise as one of the most reported cybercrime categories affecting local businesses, and many of these incidents trace back to domains whose owners believed their authentication was "set and forget". A p=none policy combined with zero monitoring is effectively an open door that the original owner has stopped watching.
For security teams managing dozens or hundreds of domains, manually checking each record is impractical. Bulk domain scanning solves this by querying DNS records in parallel and surfacing the domains that need attention first. The approach scales from a handful of marketing-related domains to entire corporate portfolios spread across Australia and overseas.
Trusted Sender Score offers a bulk domain checking tool that produces exactly this kind of inventory, allowing administrators to identify weak DMARC configurations across an entire estate in a single pass.
Understanding the three policy levels
Before scanning, it helps to understand what each DMARC policy value actually does. The summary below compares the practical differences between the three options and their impact on monitoring obligations.
| Policy value | Treatment of failing mail | Aggregate reports | Monitoring requirement |
|---|---|---|---|
p=none |
Delivered normally | Yes, sent to rua URI | High — must be actively reviewed |
p=quarantine |
Sent to spam or junk folder | Yes, sent to rua URI | Moderate — useful for tuning |
p=reject |
Rejected at SMTP level | Yes, sent to rua URI | Lowest — policy is self-enforcing |
Domains stuck on p=none with no monitoring are the only category that combines maximum permissive handling with zero visibility, making them the highest priority for remediation work.
What a p=none policy actually permits
A DMARC record with p=none tells receiving mail servers that if an email fails authentication, it should still be delivered and a report should be sent. This is useful during the early stages of deployment, when a domain owner is still discovering which legitimate senders need to be configured. However, once that discovery phase ends, leaving the policy in monitoring mode becomes a liability.
The aggregate reports that DMARC generates under p=none are valuable only if someone reads them. Many Australian organisations set up the record years ago, often to satisfy a procurement checklist, and never assigned ongoing responsibility for the data. The reports pile up in an inbox or get silently discarded by a ticketing system. In that state, the domain gives attackers free rein while the owner remains unaware.
Configuring bulk scans on the platform
To begin, sign in to your account and navigate to the bulk check interface. Paste or upload your list of domains, including all .au variants, subsidiary brands, and parked domains. The platform queries each domain in parallel and returns results within minutes, flagging the presence or absence of a DMARC record, the policy value, and whether a reporting URI is configured.
For teams who want to integrate this into CI/CD pipelines or scheduled audits, the platform also exposes an API. You can combine bulk results with IP reputation checks to cross-reference the infrastructure sending on behalf of each domain.
Interpreting results and prioritising action
After a scan, group the results into three buckets. The first bucket contains domains with no DMARC record at all; these need a record published immediately, even if it starts at p=none. The second bucket contains domains already at p=none with a valid reporting URI receiving daily reports; these are functioning as designed. The third bucket, and the one requiring urgent attention, contains domains at p=none where no reports are being received or where the URI was never configured.
For the third bucket, assign an owner, configure a working rua address, and establish a weekly review cadence. Many Australian security teams integrate this review with existing meetings rather than treating it as a separate process.
Local compliance and reporting considerations
Australian organisations handling personal information must comply with the Privacy Act 1988, and serious email-related incidents may trigger obligations under the Notifiable Data Breaches scheme. A domain that is actively being spoofed to target customers, employees, or suppliers can contribute to a reportable incident if the attacker successfully harvests credentials or delivers malware. The ACSC's Essential Eight framework also recommends enforcing DMARC as part of application hardening, which means a p=none policy without monitoring may not satisfy baseline expectations during an audit.
Reviewing the platform's legal terms helps clarify how scan data is processed and retained, particularly for organisations subject to additional sector-specific rules.
Building a repeatable remediation workflow
The goal is to move every domain from the third bucket to either p=quarantine or p=reject over time, with monitoring in place throughout the transition. Start with a baseline scan, then schedule monthly re-scans to catch new domains added through acquisitions or marketing campaigns. Pair the technical checks with a documented escalation path so that when a report shows a sudden spike in failing mail, the right person in Melbourne, Perth, or Adelaide is notified within hours rather than weeks.
Once the portfolio shows no domains at p=none without active monitoring, the bulk scan shifts from a remediation tool to a continuous assurance check, providing ongoing confidence that the email channel remains under control.