CCIT News and Notices

Clemson to enforce stronger protections for University emails sent by third-party apps

Beginning Tuesday, June 2, 2026, CCIT will strengthen the security of University communications by implementing a DMARC (domain-based message authentication, reporting and conformance) protocol for Clemson email.

What is a DMARC protocol? 

A DMARC protocol helps verify that University messages sent through third-party systems (like email marketing or customer management systems) are authorized.

Most faculty, staff and students will not notice a change in day-to-day email use. These stronger email security protections will help:

  • Reduce phishing and email spoofing that attempt to impersonate Clemson senders.
  • Strengthen trust in University email by helping recipients identify legitimate messages.
  • Align Clemson with current email security best practices.
  • Lower risk to personal and institutional data by blocking unauthorized messages.  

What to do if you send official University emails through a third-party system

Colleges and divisions that use third-party services to send messages from an @clemson.edu address for University business (like newsletters, invitations or confirmation emails) must ensure they are approved and set up correctly. If they are not approved, messages from the system may be blocked before reaching recipients.

Approved vendors authorized to send email on behalf of the University, like Microsoft, DocuSign and Workday, are already set up for DMARC compliance.

To verify that your third-party email platform is compliant with DMARC policy, initiate a review by submitting a CheckIT request online.