---
title: "The point where DORA and DMARC meet | DuoCircle"
description: "The point where DORA and DMARC meet."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/"
---

Quick Answer

DORA (the EU Digital Operational Resilience Act, in force January 17, 2023) and DMARC intersect because DORA requires financial entities, banks, insurers, investment firms, and their ICT third parties, to manage operational risk, report incidents, and prove resilience against digital disruptions, and email is the dominant attack vector. DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on SPF and DKIM to tell receiving mailboxes how to handle messages claiming to come from your domain, with three policies: none (monitor), quarantine, or reject. Deploying DMARC at p=reject across all sending and parked domains cuts brand impersonation, reduces phishing risk to customers and counterparties, and produces aggregate reports that feed DORA's ICT risk management, incident reporting, and third-party oversight requirements. For DORA-scoped firms, DMARC is one of the cheapest, fastest controls that maps directly to multiple articles of the regulation.

The point where DORA and DMARC meet

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/08/The-point-where-DORA-and-DMARC-meet.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fdmarc%2Fthe-point-where-dora-and-dmarc-meet%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=The%20point%20where%20DORA%20and%20DMARC%20meet&url=undefined%2Fblog%2Fdmarc%2Fthe-point-where-dora-and-dmarc-meet%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fdmarc%2Fthe-point-where-dora-and-dmarc-meet%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fdmarc%2Fthe-point-where-dora-and-dmarc-meet%2F&title=The%20point%20where%20DORA%20and%20DMARC%20meet "Share on Reddit") [ ](mailto:?subject=The%20point%20where%20DORA%20and%20DMARC%20meet&body=Check out this article: undefined%2Fblog%2Fdmarc%2Fthe-point-where-dora-and-dmarc-meet%2F "Share via Email") 

![DMARC meet](https://media.mailhop.org/duocircle/images/2024/08/spf-permerror-3412.jpg) 

[Digital Operational Resilience Act (DORA)](https://www.ibm.com/topics/digital-operational-resilience-act) is a regulation by the European Union that came into force **on January 17, 2023**. It makes the financial institutions and entities within the finance sector more resilient towards fraud. It strengthens banks, insurance companies, investment firms, and other financial service providers to get back on their feet after major losses and disruptions. 

## Key components of DORA

_Financial institutions are required to comply with the DORA provisions by a specified deadline_. Although there are varied timelines for different requirements that you must check beforehand. Here are its **critical elements**\-

### ICT risk management

DORA requires **financial sector** organizations to have strong internal processes for managing [Information and Communication Technology (ICT)](https://www.techopedia.com/definition/24152/information-and-communications-technology-ict) risks. Some primary processes are regular and frequent [risk assessments](https://en.wikipedia.org/wiki/Risk%5Fassessment), monitoring, and response plans for ICT-related threats.

### Incident reporting

Financial entities compliant with DORA are required to report major ICT-related disruptions and developments to the authorities as soon as possible. Delays are not appreciated. DORA has defined clear criteria for what is seen as a **big incident** that should be reported, and there are outlines of procedures that typically follow after it.

### Testing

DORA requires financial entities to conduct regular testing of their ICT systems to ensure they can withstand cyberattacks and other digital disruptions. This includes vulnerability assessments, [penetration testing](https://www.cloudflare.com/learning/security/glossary/what-is-penetration-testing/), and **scenario-based testing**.

### Third-party risk management

DORA wants the companies to also take care of the fact that [third-party](https://www.investopedia.com/terms/t/third-party.asp) services used by them are also capable of managing risks. There are certain standards for **operational resilience** for them, and these shouldn’t be ignored. 

### Oversight

Supervisory authorities in the EU have enhanced powers to oversee and **enforce the requirements of DORA**. This includes the ability to impose sanctions on entities that fail to comply.

### Information sharing

DORA encourages financial institutions and relevant authorities to share information related to [cyber threats](https://thehackernews.com/2024/08/cisa-warns-of-hackers-exploiting-legacy.html) and vulnerabilities to **improve the financial sector’s** collective [security posture](https://www.techtarget.com/searchsecurity/definition/security-posture).

[![security posture](https://media.mailhop.org/duocircle/images/2024/08/365-to-365-migration.jpg)](https://media.mailhop.org/duocircle/images/2024/08/365-to-365-migration.jpg)

## What is DMARC?

DMARC stands for Domain-based Message Authentication Reporting and Conformance. It’s an [email authentication](/resources/email-authentication) protocol that is based on its predecessors, [SPF](/content/spf-record-check?) and [DKIM](/resources/what-is-dkim), for allowing the **sending domain’s owner** to instruct recipients’ mailboxes on how to deal with emails that claim to come from their domain but are actually unauthorized. DMARC users can command recipients’ mailboxes to either do nothing with emails that fail [DMARC](/email/dmarc) checks, place them in the [spam folder](https://www.usatoday.com/story/tech/2023/06/23/emails-in-spam-folder/70350606007/), or reject their entry completely (also called [bouncing back](https://snov.io/blog/email-bounce-back/)).

## The intersection of DORA and DMARC

DMARC and DORA intersect by enhancing the security of financial institutions through robust [email protection](/content/email-phishing-protection). By putting DMARC in place, you allow the detection of unauthorized email activities, reduce security vulnerabilities, and **safeguard the business’s reputation**. When phishing attempts and suspicious emails are flagged and quarantined, [sensitive information](https://www.nist.gov/news-events/news/2024/05/nist-finalizes-updated-guidelines-protecting-sensitive-information) is prevented from being exploited against [email-based scams](https://www.interpol.int/en/News-and-Events/News/2024/Police-recover-over-USD-40-million-from-international-email-scam). 

[![cybersecurity](https://media.mailhop.org/duocircle/images/2024/08/SMTP-relay-9482.jpg)](https://media.mailhop.org/duocircle/images/2024/08/SMTP-relay-9482.jpg)

It also supports a comprehensive [cybersecurity](/) strategy by enabling the detection and response to fraudulent emails, **ensuring secure communication** in third-party contracts. Deploying DMARC across all domains provides extensive protection against phishing, spoofing, and [ransomware attacks](https://www.bbc.com/news/technology-50972890), aligning with DORA’s emphasis on [operational resilience](https://medium.com/@gieomwebsite/operational-resilience-f4eecaadc547).

## Topics

cyber securityDKIMDMARCspf 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  DMARC 6m  A guide to detecting DMARC problems using the pentesting techniques  Oct 3, 2024 ](/blog/dmarc/a-guide-to-detecting-dmarc-problems-using-the-pentesting-techniques/)[  DMARC 5m  How does DMARC make cold emailing more effective?  Jun 26, 2025 ](/blog/dmarc/how-does-dmarc-make-cold-emailing-more-effective/)[  DMARC 6m  How to safeguard your online presence with MFA and DMARC?  Apr 2, 2025 ](/blog/dmarc/how-to-safeguard-your-online-presence-with-mfa-and-dmarc/)[  DMARC 17m  SPF Record Generator: Create Accurate SPF Records for Email Authentication  Apr 1, 2025 ](/blog/dmarc/spf-record-generator-create-accurate-spf-records-for-email-authentication/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"The point where DORA and DMARC meet","description":"The point where DORA and DMARC meet.","url":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/","datePublished":"2024-08-09T20:34:33.000Z","dateModified":"2025-08-21T13:44:50.000Z","dateCreated":"2024-08-09T20:34:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/"},"articleSection":"dmarc","keywords":"cyber security, DKIM, DMARC, spf","wordCount":513,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-permerror-3412.jpg","caption":"DMARC meet","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"DMARC"},{"@type":"ListItem","position":3,"name":"The point where DORA and DMARC meet","item":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"DMARC","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"The point where DORA and DMARC meet","item":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"The point where DORA and DMARC meet","description":"The point where DORA and DMARC meet.","url":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/","datePublished":"2024-08-09T20:34:33.000Z","dateModified":"2025-08-21T13:44:50.000Z","dateCreated":"2024-08-09T20:34:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/dmarc/the-point-where-dora-and-dmarc-meet/"},"articleSection":"dmarc","keywords":"cyber security, DKIM, DMARC, spf","wordCount":513,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/spf-permerror-3412.jpg","caption":"DMARC meet","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
