Blog
DMARC Enforcement Is a People Project: Lessons from ams OSRAM and dmarcian
ams OSRAM owns roughly 250 domains. Only a handful of them send email. Today, the company’s own mail servers discard between 3,000 and 5,000 incoming messages every day that claim to come from ams OSRAM domains but fail authentication. Across Europe, many organisations have not reached DMARC enforcement yet.
Our latest CSA Live webinar looked at that gap from two sides. Steffen Siguda (Corporate Information Security Officer, ams OSRAM Group) shared how his company moved from zero to p=reject. Matia Boldrini (Professional Services Representative, dmarcian) explained what he sees across many deployments and why so many projects stall after the first step. Data from the European Commission that he presented shows that DMARC records are widely published, but DMARC enforcement is far less common. The session was moderated by Julia Janßen-Holldiek (Director, Certified Senders Alliance).
If you would like to watch the full session, the recording is available on YouTube.
The easy part comes first
Steffen’s first recommendation costs almost nothing. Most organisations hold far more domains than they use for email, often registered by marketing for individual products or campaigns. Any domain that will never send mail can be protected right away with a restrictive SPF record and a DMARC policy of p=reject. Receivers that check DMARC can then identify and reject messages that spoof those brand domains.
DKIM is similarly low effort. Most email platforms support it out of the box; in Microsoft 365, it takes a few clicks. “You raise your reputation, you raise trust for zero cost,” Steffen said.
For its sending domains, ams OSRAM began with a soft-fail SPF policy and DMARC at p=none, requesting aggregate reports to identify authentication issues before moving to enforcement. Those reports from large mailbox providers showed who was sending with ams OSRAM domains across the internet. The team also checked SPF and DMARC results on its own incoming mail. Messages that failed were tagged “potentially fake sender” in the subject line, so employees would think twice before clicking a link, and routed to an analysis mailbox. Because marketers usually receive copies of their own campaigns, that mailbox also revealed legitimate senders nobody had documented. After three to four weeks, the team had a clear picture of its sending footprint.
Matia added two warnings about this phase. DMARC is not an overnight switch: publishing p=reject before you understand your legitimate mail can disrupt the emails your business relies on. And p=none without a reporting address gives you no visibility at all. Someone must also read the reports, ideally with a tool, or they remain a pile of XML files. Steffen added a data protection note: forensic reports can contain personal data about recipients, so ams OSRAM does not use them.
Finding every sender, and the person behind it
Both speakers agreed that discovery takes the most time. At ams OSRAM, many sending systems had been introduced by marketing through external agencies, a kind of shadow IT that lives outside the company.
Spotting an unknown sender is quick. Finding its owner is not. Steffen described a lot of reverse engineering, including writing to agencies to ask who their contact at ams OSRAM was. The internal recipients of those campaign copies often knew who was behind a mailing.
Matia sees the same pattern across his customers. Reports give you the technical picture within weeks, but only the service owner can explain how a service is used and how much it matters to the business. Third-party senders often make up the majority of sending services, and vendor documentation on DMARC alignment is not always clear. For services that cannot be aligned at all, replacing them may be the better option, though that is a business decision.
Some technical choices make this phase easier. Older platforms that cannot sign with DKIM can be moved to a separate subdomain until they are replaced, as ams OSRAM did. Subdomains per use case also keep SPF records within their technical limits, which are easy to break if every discovered marketing server goes into one record. Matia recommends naming DKIM selectors so they point to the service or the key date and setting a rotation schedule. “Don’t assume that whatever the vendor suggests is good enough,” he said.
Closing the translation gap
Matia traced most stalled projects back to a single root cause. Marketing talks about campaigns, leadership about liability, IT about technical risk. He calls the distance between them the translation gap. The protocol is rarely the problem. As he put it, “it’s all about the people in the end.”
The gap shows up in practical ways. In large, global organisations, finding the person who can publish a DNS record can take days or weeks. Leadership approval alone does not solve this. Teams need clear priorities and time, or every change request turns into a new negotiation. Matia’s answer is a mandate for cooperation: a short internal charter, co-signed by an executive sponsor and the project owners. It names the project lead and a contact in each department, sets response times and a target date for enforcement, and defines an escalation path.
At ams OSRAM, the decisive backing came from the business side, with the Head of Corporate Communications firmly behind the project. It helped that both sides gained something. Security got less spoofing. Marketing gained, too; according to Steffen, the team had noticed that some of its emails were not reaching recipients. Whenever marketing wanted hundreds of servers authorised in a single domain, deliverability was the argument that worked.
Matia also recommends guiding people through the work rather than waiting for them. Sometimes a knowledge base link is enough; sometimes a short call works better. And if you have the access and approval, make the change yourself.
What enforcement pays back
The benefits look different depending on who is asking. For leadership and risk teams, a structured rollout provides a clear authentication posture to show customers, auditors and insurers. Matia noted that cyber insurance questionnaires increasingly ask specifically about DMARC, and regulations such as DORA and NIS2 are raising expectations. For marketing and sales, the payoff is continuity: campaigns, invoices and password resets keep flowing because they were identified before enforcement. IT teams often get a complete sender inventory for the first time, and duplicate or unused services come to light along the way.
For ams OSRAM, Steffen reported high delivery rates for marketing emails, stronger protection against domain spoofing and lower support effort.
He also pointed to an effect beyond any single organisation, and called it the main reason he joined the webinar. Every domain with at least basic SPF and DMARC records makes it easier for receivers everywhere to tell real mail from fake. The more organisations take that step, the better it works for everyone.
Life after reject
Reaching p=reject is a milestone, but new vendors get onboarded, configurations change and service owners leave. “The enforcement needs an owner on an ongoing basis,” Matia said. With a documented process, a new sender can be added without ever leaving reject. On the technical side, the next steps are MTA-STS with TLS reporting for inbound mail and DANE. Matia’s advice was to do both where possible. ams OSRAM has MTA-STS in the pipeline, with DNSSEC to follow.
Where to start
Matia’s closing advice was to document everything and never publish DMARC without a reporting address. Steffen’s was to start now, with the domains that never send email. “There are a lot of things that we mentioned here you can do this evening.” Tracking down shadow IT takes longer, but he estimates that most organisations can reach p=reject within one to three months.
A practical order of steps, based on both talks:
- Lock down every domain that never sends email.
- Enable DKIM on all sending platforms.
- Publish DMARC at p=none with a reporting address and assign someone to read the reports.
- Map every sender to an owner and a business purpose.
- Secure a mandate for cooperation before the first change requests go out.
- Move to enforcement, and keep an owner in place afterwards.
Or, as Steffen’s personal motto for this year puts it: complexity kills, consistency saves.