Vendor Risk: keep an eye on the companies sending mail for you
When you add a vendor to your SPF record you are letting them send as you. If they get breached, so do you. Vendor Risk keeps watching their security after the day you added them.
- Where to find it
- Monitoring & Risk → Vendor Risk
Adding vendors
- Auto-Discover scans your SPF includes and the mail infrastructure DMARCS has seen in your reports, and lists the vendors it finds.
- Watch Vendor lets you add one by hand, for a supplier that doesn't send mail but still matters to you.
What you'll see per vendor
- A security grade or risk score, and a High Risk flag if there is breach history.
- At-a-glance status for their DMARC policy, SPF, MTA-STS and BIMI.
Click a vendor for the full picture: company profile, industry compliance standards, a breakdown across eight security categories (application security, network security, DNS health, email security, patching cadence, IP reputation, web encryption, and public mentions of hacktivist activity), breach and ransomware history, and a supply-chain table of the vendors that vendor relies on.
Using it
A vendor whose grade drops, or who appears in a breach, is a prompt to ask them what happened and, if the answer isn't good, to tighten what they're allowed to do for you. Switch on the New Vendors event in your Microsoft Teams integration to have new discoveries posted to a channel.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.