CMOtech US - Technology news for CMOs & marketing decision-makers
United States
Red Sift brings OnDMARC to Microsoft Sentinel Marketplace

Red Sift brings OnDMARC to Microsoft Sentinel Marketplace

Tue, 8th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Red Sift has made its OnDMARC integration for Microsoft Sentinel available through Microsoft Marketplace, giving Microsoft customers another way to deploy the tool within their security environment.

The integration feeds DMARC forensic data and email authentication events into Microsoft Sentinel, Microsoft's cloud-native security information and event management platform. This lets security teams view email authentication signals in the same system they use for broader detection and investigation.

The move reflects phishing's continuing role in cyber incidents. According to the Verizon 2026 Data Breach Investigations Report, phishing was the initial access route in 16% of breaches, rising to 44% of intrusions involving AI-assisted methods.

For many organisations, email authentication data has remained separate from other security tools. Analysts have often had to manually match findings from email systems with identity, endpoint and network data, a process that can slow investigations and make early patterns harder to spot.

OnDMARC sends DMARC forensic reports and related authentication events into Sentinel in near real time. Once in the platform, the data can be correlated with other telemetry, allowing teams to assess suspected phishing, spoofing, business email compromise and domain impersonation alongside other alerts.

This addresses a longstanding gap in many security operations centres, where evidence of email abuse may appear before other indicators but remain outside the main workflow. Bringing those signals into Sentinel allows teams to handle them through existing detection, investigation and response processes rather than through a separate console.

Rahul Powar, Co-founder and Chief Executive Officer at Red Sift, described the issue in operational terms. "Email is where most attacks start, but the evidence usually sits in a different tool than the one your SOC team lives in," he said. "This integration puts our OnDMARC forensic data and audit logs directly into Microsoft Sentinel, so analysts can correlate email authentication activity with everything else they're already watching, without switching screens."

Microsoft framed the marketplace listing as part of a broader effort to centralise software procurement and deployment. It has used Marketplace to expand distribution for partners whose products tie into Azure and Microsoft's security stack.

"Microsoft Marketplace helps organizations and partners move faster, work smarter, and grow by connecting them with the right solutions-all in one trusted place," said Cyril Belikoff, Vice President, Microsoft Azure Product Marketing. "We're happy Red Sift is a part of the growing Microsoft Marketplace ecosystem."

Red Sift focuses on security tools spanning email, web and public key infrastructure. It says more than 1,200 teams worldwide use its products, and positions OnDMARC as its application for helping organisations move to DMARC enforcement, the stage at which fraudulent messages using a company's domain can be actively rejected.

The product's availability through Microsoft Marketplace also strengthens Red Sift's ties to Microsoft's security partner network. The company is a member of the Microsoft Intelligent Security Association, a programme that brings together security vendors whose products integrate with Microsoft systems.

DMARC gap

The announcement comes against a backdrop of uneven DMARC adoption among large organisations. Red Sift recently examined the top 100 organisations in the United States across 5,000 domains and found that while 89.5% had published an email security record, only 1,919 domains had reached p=reject, the DMARC policy setting that blocks messages that fail authentication checks.

According to that research, only 38.4% of the largest organisations had implemented full DMARC or email security enforcement. The figures suggest that many businesses have started setting up DMARC records but have not completed the final policy step needed to stop spoofed messages from reaching recipients.

That matters because business email compromise and domain spoofing remain common methods for attackers seeking to impersonate trusted brands or internal staff. Authentication failures and forensic reports can provide an early sign that such activity is under way, but their value depends on how quickly they reach analysts and whether they can be weighed against other evidence across the network.

By placing those records directly into Sentinel, Red Sift is trying to make that comparison part of routine security operations rather than a separate manual task. For companies already using Microsoft's security tools, the marketplace listing provides a direct path to add that data source to existing workflows.