Sample project record

What your firm keeps at the end of a project.

Demonstration. Sample Firm LLP is invented, and samplefirm.example is a reserved example domain nobody can register. This page shows the shape of a real record, not the result of any client’s project.

A record another administrator could pick up and follow: what was agreed, who did what, the settings before and after, the tests, and the reasons for each policy step.

1. Scope agreed

Agreed with the managing partner on 13 July 2026.

  • One domain: samplefirm.example.
  • Main mail provider: Microsoft 365.
  • Three other services that send as the firm: a case management system, a billing service and a newsletter platform.
  • Not in scope: other domains, MTA-STS and TLS reporting.

2. People

RolePart in the project
Managing partnerAgrees the scope and each policy step, and accepts the record.
Practice managerConfirms which services send email as the firm.
IT providerMakes every change in DNS and in Microsoft 365.
mailcounselBrings the sender inventory, the tests, the report review and this record.

3. Settings before and after

RecordBefore, 14 July 2026After, 12 August 2026
SPFv=spf1 include:spf.protection.outlook.com include:spf.billing.example include:spf.oldnewsletter.example ~allv=spf1 include:spf.protection.outlook.com include:spf.billing.example ~all
DKIMMicrosoft 365 signed with the tenant's onmicrosoft.com domain, which does not align with samplefirm.example. The case management system and the newsletter platform signed with their own domains.Microsoft 365 (selector1 and selector2), the case management system and the newsletter platform all sign as samplefirm.example. The billing service already did.
DMARCv=DMARC1; p=nonev=DMARC1; p=reject; rua=mailto:[email protected]

4. Services confirmed in this project

Each was tested with a real message from the firm’s own account. The result is what the receiving mailbox recorded in the message’s Authentication-Results header.

ServiceSendsPasses DMARC throughTestedResult
Microsoft 365Staff emailSPF and DKIM15 July, to Gmail and Outlook.com mailboxesdmarc=pass
Case management systemClient portal noticesDKIM, from 15 July16 Julydmarc=pass
Billing serviceInvoices and month-end statementsSPF and DKIM16 July, and the 31 July statement run in the reportsdmarc=pass
Newsletter platformUpdates to clientsDKIM, from 22 July23 Julydmarc=pass

5. Changes, each with a way back

WhenChangeMade byWay back
15 July, session 1Published the Microsoft 365 DKIM records and switched signing on for samplefirm.example.IT providerSwitch signing off in Microsoft 365.
15 July, session 1Published the DKIM records for the case management system.IT providerRemove the two records.
15 July, session 1Removed the SPF entry for a newsletter platform the firm no longer uses, once the practice manager had confirmed it.IT providerRestore the earlier SPF record in section 3.
15 July, session 1Added DMARC reporting to [email protected]. Policy left at p=none.IT providerv=DMARC1; p=none
22 JulySet up domain authentication in the newsletter platform.Practice manager, with the IT providerRemove the platform's records.
29 JulySent the office scanner's email through Microsoft 365 instead of directly.IT providerRestore the scanner's earlier mail setting.
5 August, session 2Moved the DMARC policy to p=quarantine.IT providerv=DMARC1; p=none; rua=mailto:[email protected]
12 AugustMoved the DMARC policy to p=reject, in the agreed change window.IT providerv=DMARC1; p=quarantine; rua=mailto:[email protected]

6. What the reports showed

Aggregate reports from 15 July to 11 August, from the receivers that send them. From 23 July every message from the four confirmed services passed DMARC. Two other sources appeared, and both were explained before the policy changed:

  • An office scanner emailing scans directly, failing SPF and DKIM. The IT provider identified it on 28 July and sent it through Microsoft 365 from 29 July.
  • Copies forwarded by recipients’ own mail systems, failing SPF and passing DKIM. Expected: forwarding breaks SPF, and DKIM kept these messages passing.

7. Policy decision

p=quarantine on 5 August, in the second session. Three weeks of reports, including the month-end statement run on 31 July, showed every confirmed service passing and no source left unexplained.

p=reject on 12 August, in the agreed change window. Seven days at quarantine brought no failures from confirmed services. The managing partner agreed the step, the IT provider published it, and the change was confirmed on two public resolvers.

No pct tag at any step. RFC 9989, published in May 2026, removed it, so each step changes the whole policy and gets its own observation window. The test flag t=y was not used either: receivers that do not support it would apply the stronger policy anyway.

8. Open items

ItemOwnerWhen
A recruitment platform starts sending as the firm in October. It needs DKIM for samplefirm.example before its first message.Practice manager, with the IT providerBefore it goes live
No subdomain sends email, and subdomains follow the reject policy. A new one is checked before anything sends from it.IT providerWhen one is added
MTA-STS and TLS reporting were discussed and left out of this scope.Managing partnerAt the next review

9. If legitimate email is rejected

The IT provider restores the previous DMARC record, v=DMARC1; p=quarantine; rua=mailto:[email protected], listed in section 5. The record’s time to live is 3,600 seconds, so most receivers see the change within an hour. Messages already rejected are not recovered; they have to be sent again.

10. What this record does not show

  • Every system the firm might use. It lists the services confirmed in this project.
  • What happens at receivers that send no aggregate reports.
  • Compliance. It records the work done; it is not a certificate, and not a statement that the firm meets a regulator's or an insurer's requirements.
  • Protection from every threat. DMARC does not stop a compromised mailbox, or a lookalike domain registered by someone else.

Acceptance

Accepted by the managing partner on 14 August 2026, against this record — not against a score from any checker.