Skip to content
Avanet

Set up Sophos Email DMARC Manager

DMARC Manager shows which systems send on behalf of a domain and whether SPF or DKIM is aligned for DMARC. It is powered by Sendmarc and integrated with Sophos Fusion (formerly Sophos Central). A safe rollout separates three activities: collect reports, remediate legitimate senders, and only then tighten the DMARC policy.

Quick path: Verify licensing and DNS access, capture the current state, click DMARC Reporting for the domain, publish the CNAME shown by View Setup Instructions without modification, and check it with Verify. Allow 24 to 48 hours for the first aggregate reports, then classify known and unknown senders.

Important: A DMARC migration changes authentication-report recipients and, where applicable, the managed DMARC DNS record. It does not change MX records or Sophos mailflow connectors and is not a mail-flow cutover. Leave MX records, smart hosts and connectors untouched unless a separate approved mail project requires otherwise.

Record prerequisites and the current state

You need either a Sophos Email licence or a Sophos Email Monitoring System (EMS) license. In both cases, you also need a separate DMARC Manager add-on license; DMARC Manager is not included in the base EMS licence. Setting up and operating EMS is outside the scope of this guide.

Both required licences must be active in Sophos Fusion before setup. You also need write access to the authoritative DNS zone for every sending domain, as well as an identified domain owner, DNS owner, change window and rollback plan.

Before changing DNS records, open My Products > Email Security > DMARC Manager in Sophos Fusion. The summary must be accessible. Select Manage DMARC to open the integrated Sendmarc portal; its advanced view shows DMARC authentication and compliance for the selected domain. Under Accounts > Domains, select Edit Settings for the domain and open the DMARC tab.

If DMARC Manager is missing from this path or the portal does not open, first check that either the Sophos Email licence or the Sophos Email Monitoring System (EMS) license, plus the separate DMARC Manager add-on license, is active in the correct tenant. If access is still unavailable, resolve the licence or portal access issue with Sophos. Do not continue setup in the meantime, and leave the approved DNS records unchanged.

For each domain, record:

  • the complete current DMARC record at _dmarc.example.com, including v=DMARC1, policy, percentage, rua, ruf, aspf and adkim;
  • every legitimate sending service, its return path, DKIM selector, responsible team and expected volume;
  • current aggregate and failure-report recipients, retention and privacy requirements;
  • DNS TTL, existing CNAME, TXT or NS delegations, and a zone backup;
  • baseline DMARC compliance, message volume and known forwarding paths.

A DNS name cannot hold a CNAME and other records at the same time. Before making the change, check whether the host shown by Sophos is already occupied. With Cloudflare, set a new CNAME used for this validation to DNS only; an enabled proxy can prevent resolution or verification.

Enable DMARC Reporting for a domain

  1. In Sophos Fusion, open Global Settings > Products and Services > Email, then Gateway Domains or M365 Mailflow Domains.
  2. In the DMARC Reporting column, click Not verified for the domain. If DMARC reporting setup appears, read the information and select Proceed.
  3. In the portal, open the DMARC tab and click View Setup Instructions.
  4. Copy the displayed CNAME host, target and TTL exactly into the authoritative DNS zone. Do not use example values from this guide.
  5. After publishing DNS, click Verify. If the immediate check fails, allow for the TTL or DNS propagation, then verify the host and target again.
  6. Assess optional configurations separately. Then select Save & Back and confirm that the domain status changes to Reporting.

As an alternative, Entri can publish the DNS records, but only for supported DNS providers. From record setup, select Configure DNS, then Continue. If Entri does not detect the provider automatically, select a supported provider. The DNS owner then authorises the provider; where responsibilities are separated, the administrator forwards the authorisation login to that owner. Use Change provider to correct an incorrect selection. Then select Connect and Done. Afterwards, confirm that Entri actually created the required records, return to the remaining domain configuration, and complete the existing verification and acceptance checks. Done alone does not prove that the authoritative DNS configuration is effective. For an unsupported provider, the manual method remains authoritative; the zone backup and approved rollback apply to both methods.

Sophos recommends the CNAME because later portal changes do not require another manual change to the DMARC TXT record. A TXT record is also supported, but it must be republished after each configuration change. The values displayed in the portal are always authoritative.

Monitor first and tighten policy deliberately

Under Policy Settings, start a new or unresolved domain with DMARC Policy: None. This typically corresponds to p=none: receiving systems report results without the DMARC policy requesting quarantine or rejection. It is a monitoring phase, not a finished protection posture.

Under Aggregate Reports > Reports Will Be Sent To, enter only additional approved recipients that are genuinely required. Under Failure Reports, you can enable Report Processing: Enabled and select the scope in Report Options. Failure reports can contain personal or message-related data, so recipients and retention must be approved in advance.

Choose Strict or Relaxed deliberately under Alignment Settings. DMARC passes when at least one aligned path succeeds: SPF with a matching envelope-from domain or DKIM with a matching signing domain. An SPF or DKIM pass without alignment to the visible From domain is not sufficient.

After at least two weeks of representative data and remediation of legitimate sources, progress in stages from None to Quarantine and later Reject. Before each stage, check business-critical systems, forwarding, subdomains and the approved rollback. Apply the configuration with Save; a higher score alone does not justify enforcement.

Understand the reporting-migration boundary

The current migration guidance does not establish operational steps for moving report delivery from another platform to DMARC Manager. Existing providers can manage report recipients, DMARC TXT records or DNS delegations differently. Before changing any report destination, administrators must clarify the provider-specific handoff, coexistence, retention and rollback requirements with the current provider and Sophos.

A reporting change is not a mail-flow cutover: do not change MX records, smart hosts or Sophos mailflow connectors as part of it. Never publish two DMARC records for one domain, and do not assume that report recipients can run in parallel unless both providers explicitly support and approve that arrangement.

Interpret the summary and portal reports

Sophos Fusion shows the summary under My Products > Email Security > DMARC Manager. At least one domain must be Reporting and generate outbound traffic. Initial data normally appears after 24 to 48 hours. Use Domain and Date Range to select one domain or All domains and a period; the default is 30 days and custom ranges can cover up to 365 days.

Domain Score and Risk Level help prioritise work. The current Domain Score comprises Impersonation (80%) from DMARC, SPF and DKIM, Branding (5%) from BIMI, and Privacy (15%) from TLS-RPT and MTA-STS. The published conditions are:

  • missing or misconfigured DMARC, or None, produces a low DMARC assessment; Quarantine is moderate and Reject is high. Missing SPF/DKIM configuration or alignment can reduce the Impersonation component;
  • no BIMI produces a Branding score of 0, while valid BIMI with a VMC produces 5;
  • Privacy depends on complete TLS-RPT and MTA-STS records and on MTA-STS being In Testing or Enforced. With both records present, In Testing produces 4 and Enforced produces 5. Sophos documentation gives conflicting values for incomplete intermediate states, so do not derive an exact formula for them.

Treat the score as a delayed configuration indicator, not a decision that the domain is ready for enforcement. Changes are not immediate and may reach the score the next day; the score alone must not trigger policy tightening. Also evaluate:

  • Passing, Failing and Forwards in the compliance trend;
  • new source countries, IPs or hostnames and abrupt volume changes;
  • high-volume senders with low compliance;
  • mismatches between the expected platform, SPF result, DKIM result and alignment.

Use View report or Manage DMARC for details. The Email Senders report helps associate IPs, hostnames, volume, Compliance, Deliverability and Reputation. Failure Reports provides message-level detail when available and approved. TLS-RPT Reports covers TLS transport reporting and is not the same as DMARC authentication.

Approve a sender only after technical and organisational confirmation. A familiar brand or plausible hostname is not enough; owner, sending purpose, SPF or DKIM configuration, and alignment must agree.

Accept the change and operate it continuously

Setup is accepted when:

  • Sophos Fusion shows Reporting and authoritative DNS returns the expected value;
  • aggregate reports for current outbound traffic arrive within the expected 24-to-48-hour window;
  • every business-critical sender has an owner and an explained alignment result;
  • policy, alignment and approved additional recipients are in the change log.

Configure alerts for compliance drops, new senders and DNS verification problems to reach a monitored mailbox. If an alert is missing, also check the spam folder for messages from alert@sophosdmarc.com. Review unknown senders, retired services, DNS status and policy suitability monthly.

Troubleshoot common problems systematically

Verification fails: Query the authoritative DNS for the exact displayed host. Eliminate typos, duplicated zone suffixes, CNAME conflicts, TTL delays and the Cloudflare proxy. Then select Verify again; do not experiment with several competing records.

No data after 48 hours: Confirm the domain is Reporting, generates outbound mail and has an effective DMARC record that routes reports to the manager. Check the timezone and the Domain and Date Range filters. Allow longer for a low-volume domain.

A legitimate sender fails: Investigate envelope-from, visible From domain, DKIM signing domain and selector separately. Forwarding can break SPF; aligned DKIM may still allow DMARC to pass. Do not broadly relax aspf or adkim; fix the responsible service first.

An unknown sender appears: Do not approve it immediately. Capture the IP, hostname, volume, countries, time window and affected domain, identify an internal owner, and treat it as abuse if no authorisation exists.