Email Security (DMARC)

ASU is a big target for spoofed and fraudulent email. In recent months, the ASU Information Security Office has seen a large rise in email spoofing tactics and a more surgical approach from bad actors. To protect legitimate ASU emails from being confused or mistakenly identified as spoofed or fraudulent email, ASU is putting in place a technology that will authenticate legitimate email, allowing it to enter the asu.edu domain and reject potentially fraudulent email.

The technology is called Domain-based Message Authentication, Reporting & Conformance, or DMARC.

What is Domain-based Message Authentication, Reporting & Conformance (DMARC)?

DMARC is an email authentication software that ensures legitimate email is properly identified. Once ASU implements DMARC on ASU mail servers, incoming email will be reviewed and authenticated by DMARC. Email that passes the authentication protocol can be trusted and will be delivered to asu.edu email addresses. Email that fails authentication will be quarantined or rejected. 

How does this affect Stova?

Stova is considered a third-party mail vendor. Stova's email servers send email on behalf of the asu.edu domain. So steps must be taken by Stova users to identify their emails are coming from the Stova platform.

To do this, Stova users must make a small change to the email address domain of emails being sent from event registrations and the Marketing module.

In order to be DMARC compliant, users must use the email domain of "@a.asu.edu" ("a." in front of the "asu.edu") in the From or Sender's email fields. This change affects the Event Emails in the Registration module and emails sent from the Marketing module.

How to be DMARC Compliant within Stova, or Bringing Your "a." Game

Marketing Module

When creating an email in the Marketing module, go to the Edit Email Details>Email Details tab.

In the Email Details section, use the domain "@a.asu.edu" in the Sender's Email field.

.


Event Registration - Event Emails

When creating or editing an event, check all the event emails on the Event Info>Event emails page by clicking the edit button.

In the General Details section of each email, use the domain "@a.asu.edu" in the From (email) field.

.

No change for Reply-to email

You should continue to use the standard email address domain - @asu.edu - for email addresses in the Reply-To fields.

DO NOT use the "@a.asu.edu" domain in the Reply-to email field. 

History

The ASU Stova account was upgraded July 2021. Users will only be able to use either "@a.asu.edu" or alternative DMARC domain (see below) in the From or Sender fields.

Users will see an error message if they attempt to use a non-DMARC email domain.

.

 

Recommended Actions

We recommend all Stova users begin using the "@a.asu.edu" domain in all event registrations and email campaigns immediately.

If your unit or team currently does not have an ASU email address, we suggest you explore either (1) requesting a 'Mail Enabled' Public Folder, or (2) use the ASU Salesforce Case Management service for receiving and managing email. You can request these services through Service Now on MyASU. In both cases, you can have a new ASU email address created for your unit/team.

Alternative DMARC Domains

Does your unit have a need for an alternative to the "a.asu.edu" domain? If so, read this page.

Questions

For questions regarding DMARC at ASU, please feel free to reach out to DL.PROJ.DMARC@exchange.asu.edu

Information on DMARC is available on Service Now.