Hardening Reference
Phishing: what the DMARC reports show that inboxes never will
Somebody is sending mail with your domain on it and you have no way of seeing how much.
The short answer
Phishing is impersonation used to harvest credentials or payments — and for a site owner it arrives along two distinct routes that need two distinct answers.
Route one borrows your domain to send mail you never authorised, which is a DNS and authentication problem you can measure and close. Route two targets you directly, with a convincing suspension notice aimed at your hosting login, which is a habit problem no record can fix.
By the HostingFast team · Reviewed 12 August 2026
0
Hand-waving in this entry
100+
Entries wired to each other
Real
Numbers you can reproduce
Free
To read, no gate
The spoofing route is the one with instrumentation attached. Publish a DMARC record with a reporting address and receivers start sending you daily XML summarising every message claiming to be from your domain: how many, from which sending addresses, and whether SPF and DKIM aligned. Before that record exists you are blind; a day after it exists you have a census.
That data is what makes enforcement safe. Nearly everyone who breaks their own mail by publishing p=reject does it without having read a single report first, and discovers only afterwards that their invoicing system or their newsletter platform was never aligned.
Reading an aggregate report without a paid tool
The XML is unpleasant but small. Each record names a sending address, a count, and the SPF and DKIM results with their alignment verdicts. Sort by count and the top few rows will be your own mail servers; anything below them sending in volume is either a service you forgot you authorised or somebody else entirely.
The distinction that trips people up is alignment. A message can pass SPF against the envelope sender and still fail DMARC, because the domain that passed is not the domain in the visible From header. Alignment is the check that closes that gap, and it is the column to read first.
A rollout that does not strand your own mail
Start at p=none with reporting on and change nothing else for a fortnight. Use the reports to find every legitimate sender — the site's own transactional mail, the CRM, the accounting package, the marketing platform — and get each one aligned with SPF and DKIM.
Then move to p=quarantine, watch for a fortnight, and only then to p=reject. Each step is one DNS edit and the whole exercise costs a month of patience. Skipping the middle step is how a business finds out that its invoices have been going to junk since Tuesday.
The half that never touches your DNS
A registration such as yourbrand-support.example is a different domain with its own perfectly valid records. Nothing in your zone constrains it, and no policy you publish will stop a message it sends. That half is monitoring and takedown requests, not configuration.
The same is true of the notice aimed at you. Urgency arriving in the same message as a sign-in link is the shape to distrust. Check the sending domain, never follow the link, and open the panel from your own bookmark instead. A genuine problem will still be there when you arrive.
What the platform already handles
Outbound mail from hosting accounts here goes through MailChannels, which keeps genuine mail from your domain out of junk folders and gives receivers a consistent sending reputation to judge. Spam and virus screening runs on every mailbox from the day it exists.
Publishing and aligning the records is still yours to do, because only you know every service sending on your behalf. Neighbouring entries: DMARC, SPF, DKIM and Two-Factor Authentication.

Email authentication, without the acronym soup
Three records, one dependency order, and one report format that tells you whether any of it is working. That is the whole subject, and this reference sets it out in the order you have to do it in.
Mailboxes on your own domain come with every hosting plan, with webmail plus IMAP, POP and SMTP for whatever client you already use.
- Records in dependency order
- Report fields explained plainly
- Enforcement rollout with timings
- Written by people who run mail
Why HostingFast
Standard on every plan
Two routes, two answers
Domain spoofing is a records problem you can measure. A fake suspension notice is a habit problem no record fixes.
Reports before enforcement
Publish reporting first and you get a census of every sender using your name, free, within a day.
Alignment made clear
Why a message can pass SPF and still fail DMARC, and which column in the report tells you so.
A rollout with dates on it
None, quarantine, reject — a fortnight each, one DNS edit at a time.
Honest about the limits
A lookalike registration never touches your zone, so no policy you publish will stop it.
What we already do
Outbound mail routed through MailChannels and screening on every mailbox from day one.
Quick Start
From order to online
- 1
Publish reporting before policy
A DMARC record at p=none with a reporting address costs nothing and turns an invisible problem into a daily list of senders.
- 2
Align every legitimate sender
Work down the report by volume. Each service sending as your domain needs SPF and DKIM aligned before enforcement, or it stops arriving.
- 3
Move up one step at a time
None, then quarantine, then reject, a fortnight apart. The gap is what stops you discovering a broken sender from a customer.
Built In
Loaded onto every plan
- Staging environments for testing changes before they ship
- WordPress Toolkit, with updates handled for you
- NVMe SSD storage on every tier, not just the expensive ones
- 99.9% uptime as the target, monitored around the clock
- Human support on duty every hour of every day
- Your existing site moved over by our engineers, free of charge
- WordPress and 400+ other applications installed in one click
- Email addresses that run on your own domain name
- Zero setup charges — there is no joining fee, ever
- Year one of your domain free when you order annually
Frequently Asked
What people ask us most often
How do I read a DMARC aggregate report without buying a tool?
Open the XML and sort the records by message count. Each one gives a sending address, a volume and the SPF and DKIM results with their alignment verdicts. Your own servers will be at the top; the rows underneath are either services you authorised and forgot, or the impersonation you published the record to find. A spreadsheet is enough for a small domain.
Will p=reject stop mail my own site and systems send?
It will, if any of them are unaligned — and that is exactly why the reporting phase comes first. Site notifications, invoicing, CRM and newsletter platforms all commonly send as your domain without DKIM signing under it. Get every one of them aligned at p=none, then quarantine, then reject.
Does the platform authenticate my outbound mail for me?
Outbound mail from hosting accounts is routed through MailChannels, which handles delivery reputation, and DKIM signing for your domain is configured from cPanel. Publishing SPF, DKIM and DMARC records in your DNS is your call to make, because only you know the full list of services sending on your behalf. Support will check your records if you ask.
Someone has registered a domain that looks like mine. What now?
Nothing in your DNS reaches it, so treat it as a brand matter rather than a mail matter: report it to the registrar hosting it, report the phishing pages to the browser vendors, and warn customers on a channel you control. Meanwhile enforce DMARC on your real domain so the easier attack stops being available.
Keep reading
Malware
Injected code running on your account, found by timestamp, checksum and obfuscation string.
Two-Factor Authentication (2FA)
Second factors ranked by what they actually resist, and the order to enable them in.
How to Test Your Website Speed
Splitting a response time into its four parts and fixing the one that is costing you.
WordPress Hosting
Managed WordPress on LiteSpeed, with staging copies and daily backups included.
VPS Hosting
KVM virtual servers with root access, edge filtering and one flat monthly price.
Changing hosts? Run through our checklist first.
A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.
Lock the domain down, then the login.
Mailboxes on your own domain, screening as standard, and outbound mail routed for deliverability on every plan.
View WordPress Hosting plans