SECURITY PROGRAM // ACTIVE ENGAGEMENT
Email Security & DMARC
2026-03-18 // V1.0
IMPL
IMPLEMENTATION_RECORD
Email Security & DMARC
DMARC enforcement at reject policy with SPF and DKIM alignment. External forwarding rules blocked. Material Security enrolled for advanced email protection.
QUICKSTARTDEPLOYED // STABLEIaC // TERRAFORM
SERVICEEmail Security & DMARC
PACKAGEQUICKSTART
DEPLOYED2026-03-18
STATUSDEPLOYED // STABLE
THREAT_VECTOR //
Email impersonation and domain spoofing are primary vectors for business email compromise — this control prevents unauthorized parties from sending email as your domain.
DEPLOYMENT_CHECKLIST
DMARC policy set to rejectPASS
SPF record aligned and validPASS
DKIM signing enabled for all domainsPASS
External forwarding rules blockedPASS
Material Security enrolledPASS
CONFIGURATION
| SETTING | VALUE |
|---|---|
| DMARC Policy | p=reject; rua=mailto:dmarc@threatunknown.com |
| SPF Record | v=spf1 include:_spf.google.com ~all |
| DKIM | Enabled (2048-bit RSA) |
| Forwarding Rules | Blocked via policy |
FRAMEWORK_MAPPING
SOC_2_READINESSTRUST SERVICES CRITERIA SATISFIED
CC6.7Controls restricting unauthorized transmission or movement of information
CC6.8Controls preventing introduction of unauthorized or malicious software
These controls form part of the evidence base for your SOC 2 Type II audit.
NIST_CSFSECURITY FRAMEWORK FUNCTION
ProtectImplement safeguards to limit the impact of potential events
DetectIdentify when security events occur
BASELINE_DELTA
BEFORE // BASELINE STATE
- No DMARC record — anyone could send email impersonating your domain
- No SPF alignment verification
- DKIM not configured
- External forwarding rules permitted
- No inbox-level threat protection
AFTER // CURRENT STATE
- DMARC policy at reject — unauthorised senders blocked by receiving mail servers
- SPF record published and validated
- DKIM signing enabled (2048-bit RSA)
- External forwarding rules blocked at admin level
- Material Security enrolled on all 18 mailboxes
CURRENT_HEALTH
DMARC_PASS_RATE98.7%TARGET: >98%
DMARC_POLICYrejectTARGET: reject
EXTERNAL_FORWARDING_RULES0TARGET: 0
CONTROL_HISTORY
EVIDENCE_REFERENCES
| ARTIFACT | TYPE | LOCATION | REF | DATE | WHAT THIS PROVES | |
|---|---|---|---|---|---|---|
| DMARC Q1 Aggregate Report | CONFIG EXPORT | dmarcian | dmarc-aggregate-q1-2026.html | 2026-04-02 | Confirms DMARC policy advanced to reject based on aggregate report analysis — identifies the unauthorised Mailchimp sending source that was remediated | VIEW |
| DNS Record Verification | CONFIG EXPORT | Cloudflare Dashboard | dns-verification-2026-03-18.txt | 2026-03-18 | Proves SPF, DKIM, and DMARC records are correctly published and aligned — direct evidence for CC6.7 email transmission controls | VIEW |
| Material Security Enrollment | SCREENSHOT | Material Security | material-security-enrolled-2026-03-18.svg | 2026-03-18 | Proves inbox-level threat protection is active for all mailboxes at implementation date | VIEW |
| Terraform Plan Output | TERRAFORM | https://github.com/ThreatUnknown/meridian-security-baseline | pr-17-terraform-plan.txt | 2026-03-18 | Confirms DNS changes were deployed via code with full change history | VIEW |