Executive summary: Today, Red Sift is announcing the extension of their Microsoft Intelligent Security Association (MISA) partnership by bringing email authentication events into Microsoft Sentinel, Microsoft's cloud-native Security Information and Event Management (SIEM) solution. Security operations center (SOC) teams receive real-time alerts to identify and respond to active threats that can indicate early phishing campaigns, Business Email Compromise (BEC), and reconnaissance activity. The Red Sift OnDMARC Integration for Microsoft Sentinel is now available in the Microsoft Marketplace for existing OnDMARC customers.
Key takeaways:
- DMARC forensic data, like SPF and DKIM results, and email authentication events from Red Sift OnDMARC can now stream into Microsoft Sentinel in real time, with no manual export.
- SOC teams can surface suspicious senders, domains, and login anomalies without leaving their workflows.
- Potential phishing and spoofing threats are detected early for faster triage.
- This pre-built integration extends Red Sift's standing as an official member and only one of two recommended DMARC providers within the Microsoft Intelligent Security Association (MISA).
Red Sift OnDMARC, which helps organizations reach and hold DMARC (Domain-based Message Authentication, Reporting and Conformance) enforcement, now sends telemetry events like DMARC data and other forensics through our integration with Microsoft Sentinel, available today in the Microsoft Marketplace.
Why we integrated with Microsoft's SIEM
Email is still one of the front doors attackers use most. Phishing was the starting point for 16% of breaches last year, according to Verizon's 2025 Data Breach Investigations Report, and around 60% of breaches involved a human element at some point in the chain. Email authentication data is often what tells you a spoofing attempt is underway, which makes it exactly the kind of signal a SOC team wants next to everything else they watch.
A security operations center runs on its SIEM. An analyst spends their shift in SIEM workflows where they track alerts, monitor threat activity, and run investigations. DMARC forensics has formally lived outside of those workflows, in reports owned by the team running email authentication and out of reach for the SOC. But with DMARC data now flowing into Microsoft's SIEM as they occur, SOC analysts now have tighter control over their entire security ecosystem.


Key use cases for Microsoft Sentinel & Red Sift OnDMARC
With the Red Sift OnDMARC Integration for Microsoft Sentinel turned on, two streams flow into your Sentinel workspace in real time: OnDMARC forensic data, including DMARC, SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) results, and Red Sift platform audit logs covering user login activity.
From there, these events behave like any other Microsoft Sentinel data source. A SOC analyst can write detection rules against them, join them to endpoint or identity signals in a correlation query, fire alerts, and pull them into the workbooks and hunting queries the team already runs.
Take a real case. A finance team flags an invoice email that looks wrong. Today, an analyst can run a single query in Microsoft Sentinel, see the OnDMARC forensics for that domain alongside other threat activity, and close the question out in a single view. Turn that same logic into a detection rule or add it to a watchlist, and the next spoofed domain triggers an alert on its own instead of waiting in a report for someone to open it.
Applied across a workspace, those threat signals can be triaged immediately to shut down domain impersonation threats.
Activating the integration through the Microsoft Marketplace
The integration ships as an Azure application in the Microsoft Marketplace and is built for existing OnDMARC customers with an active subscription and a Microsoft Sentinel workspace. All you need to do is log in to the Red Sift platform and turn it on.

Red Sift is an official member of the Microsoft Intelligent Security Association (MISA), and Red Sift OnDMARC is one of two recommended DMARC partners within MISA that delivers phishing and BEC protection for Microsoft 365 customers.
Natalie Hays is Senior Product Marketing Manager at Red Sift, where she drives go-to-market strategy and product positioning across the company's entire product portfolio.




