Security & Deliverability

What It Took a 153-Year-Old Community Bank to Reach DMARC Enforcement

Florence Bank, a Massachusetts community bank founded in 1873, has moved its domain to an enforced DMARC policy after a four-month engagement with EasyDMARC. The vendor published a case study on 16 July. Case studies tend to stay high level, so we asked the engineer who did the work what the bank’s email environment actually looked like on the way to enforcement.

Nshan Manoukian, a senior DMARC implementation engineer at EasyDMARC, worked with the bank throughout the project. His answers are a useful corrective to the idea that DMARC enforcement is mostly about publishing a DNS record.

What a community bank’s sending stack actually looks like

The most valuable detail in any enforcement story is the sender inventory, and Florence Bank’s is instructive. Manoukian built it by analysing the bank’s SPF includes and sending IPs alongside its DMARC aggregate reports, producing what he describes as “a complete inventory of their legitimate email sources.”

The named sources tell the story of modern banking infrastructure. Jack Henry, the core banking processor, sends email on the bank’s behalf. Creatio, the bank’s CRM, sends through SendGrid as its underlying email infrastructure, which means authenticating one vendor required understanding a second vendor nested beneath it. Multiple Amazon SES environments were in the mix. So was KnowBe4, the security awareness platform, meaning the bank’s own phishing simulation tool needed the same authentication treatment as any other sender. A long tail of further third-party services rounded out the list.

Two of those deserve a second look. The Creatio arrangement is the increasingly common pattern of a SaaS application riding on a CPaaS provider’s sending infrastructure, where SPF, DKIM and alignment behaviour are determined by a company the customer never contracted with. And the plural in “Amazon SES environments” is the quiet signature of shadow email infrastructure, the kind that only surfaces when aggregate reports force a full accounting.

The SPF wall came first

Before any of that could be aligned, the project hit the SPF 10 DNS lookup limit, the ceiling that a vendor-heavy sending stack reaches quickly. The bank cleared it using EasyDMARC’s managed SPF product, which belongs to the category of macro-based dynamic SPF tools that resolve sources at evaluation time rather than stacking static includes. However it is achieved, getting under the lookup limit is a precondition for everything that follows, because SPF records that exceed it fail silently.

The discipline was in the waiting

With sources configured, the temptation is to enforce immediately. Manoukian did the opposite. He recommended holding the domain at a monitoring policy for a further two to three weeks while the updated aggregate reports confirmed that legitimate traffic was consistently passing authentication and alignment, and that no new legitimate sources were appearing.

“Because all of the preparation had already been completed, the transition to enforcement was straightforward,” Manoukian said. The enforcement step itself was uneventful, which is precisely the point. The work is in the inventory and the validation, not the policy change.

Four months, in context

EasyDMARC’s own deployment data puts its enterprise average at 55 days to enforcement. Florence Bank took roughly four months. That gap is not a criticism. A regulated community bank whose email flows through a core banking processor, a nested CRM stack and multiple cloud environments is exactly the profile that takes longer, because vendor coordination, not DNS, is the constraint. The bank’s own case study says most of the effort went into coordinating with vendors.

The wider context makes the destination notable regardless of the journey’s length. EasyDMARC’s 2025 Global DMARC Adoption Report found only 7.7% of the world’s top 1.8 million email domains protected by a p=reject policy. A community bank at full enforcement sits in a small minority of its sector, and of email senders generally.

For financial institutions still sitting at p=none, the transferable lesson from this project is unglamorous. Build the complete inventory before touching policy. Expect the nested vendors to take the time. Hold at monitoring until the reports have been boring for weeks. Then the enforcement step is the easiest part of the project.

EasyDMARC is an Enterprise Member of emailexpert. Members do not review or approve editorial coverage before publication.

Reported from primary sources by people who work in email. AI assists; it doesn’t decide what’s true.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory