DMARC for title companies, in plain English
DMARC is the setting that decides whether a criminal can send email from your exact address. Most small title agencies either don't have it or have it switched to a mode that stops nothing.
The problem it solves
Email was designed without a way to prove who sent a message. Anyone can put closings@yourtitleco.com in the From line. Unless your domain tells the world otherwise, most mail servers will deliver that message to your buyer, with "updated wiring instructions" inside.
DMARC is how your domain tells the world otherwise.
Three records, one job
- SPF is a list of the services allowed to send email for your domain.
- DKIM is a digital signature your email provider adds to each message, so the receiver can confirm it wasn't forged or altered.
- DMARC is the policy. It tells receiving mail servers what to do with a message that fails both checks.
The three DMARC settings
| Policy | What happens to forged email | Are you protected? |
|---|---|---|
p=none | Delivered normally. You get reports about it. | No |
p=quarantine | Treated as suspicious, usually sent to spam. | Mostly |
p=reject | Refused outright. The client never sees it. | Yes, against exact-domain forgery |
When we checked the public records of 161 Maryland title agencies with their own domain in September 2026, 74 had no DMARC record at all and another 39 were set to p=none. That means roughly 7 in 10 could be impersonated by email.
How to get to "reject" without breaking your email
- List everything that sends email as you. Your mailbox provider is the obvious one. The ones people forget: closing software notifications, the office scanner, e-signature tools, marketing newsletters, and your website's contact form.
- Fix SPF and turn on DKIM for each of those services.
- Publish DMARC at p=none with a reporting address, and read the reports for two to four weeks. This is the only good use of p=none: a short diagnostic stage.
- Move to quarantine, then reject. Once the reports show your legitimate mail passing, tighten the policy.
- Keep watching. New tools get added, and reports show who is trying to impersonate you.
What DMARC doesn't do
DMARC protects your exact domain. A criminal can still register yourtit1eco.com and send from that, or steal a staff password and send from a real mailbox. Pair DMARC with look-alike domain monitoring and two-step sign-in on every account. See signs your email has been hacked.
Check yours now
Our free spoofing check reads your domain's public records and tells you which of the three settings you have.
Sources
- DMARC overview (dmarc.org)
- Email sender guidelines (Google)
- Sender best practices (Yahoo)
Common questions
Is p=none enough to stop someone spoofing my title company's domain?
No. p=none is monitor-only mode. It asks other mail servers to send you reports about email that fails verification, but that email is still delivered. Protection begins at p=quarantine and is complete at p=reject.
Will turning on DMARC break our email?
It can if it's rushed. Before enforcing, you need to confirm every service that legitimately sends email as your domain, such as Microsoft 365, your closing software, scanners, and marketing tools, and make sure each one passes. Done in the right order, your real email keeps flowing and only forgeries are refused.
We use Microsoft 365 through GoDaddy. Can we still use DMARC?
Yes. DMARC, SPF, and DKIM are DNS records on your domain, and they work with Microsoft 365 purchased through GoDaddy. The steps to turn on DKIM signing are slightly different from a direct Microsoft account.
Does DMARC stop all wire fraud email?
No. It stops email forged from your exact domain. It does not stop look-alike domains that are one letter off, or email sent from a real mailbox whose password was stolen. Those need monitoring and two-step sign-in.
Do Google and Yahoo require DMARC for a small title agency?
The Google and Yahoo sender rules that took effect in February 2024 require DMARC only for senders of more than 5,000 messages a day, and Microsoft announced similar rules for high-volume senders in 2025. A small agency is not bound by them. The reason to do it is spoofing protection, not a mandate.