Fromenance

Compare

Fromenance vs DMARC and BIMI

DMARC authenticates a domain and Fromenance communication provenance authenticates a communication, so they answer different questions and you need both. A phishing message sent from a lookalike domain passes SPF, DKIM, and DMARC for the attacker's own domain; Fromenance answers whether your institution actually sent that message to that customer.

What each one does

DMARC compared with Fromenance
QuestionDMARC (with SPF, DKIM, BIMI)Fromenance
What does it authenticate?A domain. SPF says the sending server is authorized for the domain; DKIM signs parts of the message for a signing domain; DMARC requires alignment between them and the visible From.A communication. A registered record that this institution sent this message to this recipient at this time, checked by a verify code, a recipient HMAC, and a content fingerprint.
Who sees the result?Receiving mail servers, and the domain owner through aggregate and forensic reports. The customer sees nothing, except a logo when BIMI is configured and the client supports it.The customer, in a reply from the institution's domain or on the institution's verify page, in seconds.
Does it stop lookalike domains?No. A message from northfield-bank-secure.com with correct SPF, DKIM, and DMARC for that domain passes. DMARC only governs the real domain.A lookalike message is not in the registry, so it returns Not verified, and the lookalike domain becomes an indicator.
Does it stop free mail and compromised accounts?No. Mail from a Gmail account or a compromised vendor domain authenticates for that domain.Same answer: not registered, Not verified, sender address extracted as an indicator.
Does it handle display name impersonation?No. DMARC does not evaluate the display name.The display name is irrelevant to matching. Only the registry counts.
What does the customer learn?Nothing they can act on. Authentication results live in headers most clients hide.A locked verdict with a next step and the institution's fraud contact.
What does the institution learn?Aggregate reports about who is sending as the real domain, useful for finding unauthorized senders and misconfigured vendors.Every lure a customer doubted, with its indicators, delivered by the person it targeted. Replay flags show which templates are being copied.
DeploymentDNS records and a policy ramp from none to quarantine to reject, often months of vendor discovery.One TXT record, one redirect rule, one footer, one registration path. Fromenance requires that the forwarding hop pass DKIM or ARC, so it builds on your DMARC work rather than replacing it.

Why a lure passes DMARC

DMARC is valuable against direct spoofing of your protected domain. Attackers stopped doing that years ago.

What attackers send instead

  • Lookalike domains: bank-security.com, bankalerts.net, Unicode homoglyphs
  • Free mail accounts with your display name
  • Compromised legitimate domains, including your vendors'
  • Legitimate SaaS sending infrastructure with your logo pasted in
  • SMS, QR codes, and images that never touch DMARC at all

Each of these authenticates correctly for the domain it was sent from. DMARC is doing its job. The job is not the customer's question.

What BIMI adds and does not add

BIMI shows your logo next to messages that pass DMARC with a strict policy, in clients that support it, if you hold a verified mark certificate. It is a positive signal that some customers in some clients will notice.

It does not give the customer a way to ask about a message that lacks the logo, which is every lure. And logos are exactly what attackers paste into their messages. Fromenance gives the customer an action: forward it, paste it, get an answer.

Why both

Fromenance depends on your DMARC work. Inbound mail to your tenant inbox is processed only when the forwarding hop passes DKIM or ARC for a domain you own, and the recommended reply identity is a DKIM signed subdomain. Keep DMARC at reject. Add the layer the customer can see.

Run a 60 to 90 day pilot on one communication stream.

Fraud alerts or transaction alerts are the best first stream. You get a written report of verification volume, verdict distribution, campaigns discovered, and intelligence yield.