DMARC Policy Enforcement Update
DMARC Policy Enforcement Update
CUIT is looking to implement changes soon. Columbia University Information Technology (CUIT) will begin enforcing a DMARC policy of p=reject across all levels of Columbia-managed domains. This change represents the final phase of our DMARC implementation. It is intended to significantly reduce email-based spoofing, phishing, and other forms of domain impersonation by preventing unauthorized systems from sending email on behalf of Columbia domains.
Once a domain is set to a DMARC policy of Reject, any email that fails DMARC alignment checks (SPF and/or DKIM) will be rejected by receiving mail systems, rather than quarantined or delivered. As a result, emails sent from third-party platforms, cloud services, or on‑premise systems that are not properly authenticated will not be delivered unless they are correctly configured to meet DMARC requirements.
CUIT recognizes that this enforcement may impact existing email workflows that rely on third-party senders or legacy systems. All affected services must be reviewed and remediated prior to enforcement by ensuring proper SPF, DKIM, and DMARC alignment. Units and vendors that do not complete this work in advance may experience mail delivery failures once their domain moves to a Reject policy.
This page will be updated periodically to reflect:
- Which domains have already transitioned to a DMARC policy of Reject
- Upcoming domains scheduled for enforcement
- Any additional guidance or remediation resources as they become available
We strongly encourage all domain owners, administrators, and service operators to review their sending infrastructure and coordinate with CUIT well in advance of their domain’s transition. Early validation and testing are critical to avoid unintended disruptions to legitimate email communications.
For questions, impact assessment, or assistance with DMARC compliance, please contact CUIT through the appropriate support channels.
