DMARC explained
DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) ties SPF and DKIM to the address people actually see in the From: header, tells receivers what to do with mail that fails, and asks them to send you reports. It's what actually stops other people from sending mail that looks like it comes from your domain.
What a DMARC record looks like
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; pct=100; adkim=r; aspf=r"
| Tag | Meaning |
|---|---|
v=DMARC1 | Required, and must come first. |
p= | Required policy for failing mail: none (monitor only), quarantine (spam folder) or reject (refuse it). |
sp= | Policy for subdomains. Defaults to p. |
rua= | Where receivers send daily aggregate reports (mailto: addresses). |
ruf= | Where to send per-message failure reports. Few receivers send them. |
pct= | Percentage of failing mail the policy applies to (default 100). Useful during rollout. |
adkim= / aspf= | Alignment mode: r relaxed (default; subdomains of the same organizational domain match) or s strict (exact match). |
Alignment: why SPF and DKIM passing isn't enough
A message passes DMARC when either SPF passes for a domain that aligns with the From: domain, or a DKIM signature passes with a d= domain that aligns with it. A newsletter sent through a third-party tool might pass SPF for the tool's own bounce domain and still fail DMARC, because that domain isn't yours. The fix is to set up the tool's custom return-path or DKIM domain on your own domain.
p=none vs p=quarantine vs p=reject
- p=none only monitors. It's the right first step, and Gmail and Yahoo require at least this from bulk senders since 2024, but it doesn't protect you from spoofing.
- p=quarantine sends failing mail to spam.
- p=reject blocks it outright. This is the goal for most domains, and it's required to display a BIMI logo (quarantine also qualifies).
A safe rollout plan
- Publish
p=nonewith arua=address and read the aggregate reports for two to four weeks. - Fix every legitimate sender that fails: add it to SPF, turn on DKIM signing with your domain, or move it to a subdomain.
- Move to
p=quarantine, optionally withpct=25and then 50 and 100. - Move to
p=rejectonce reports stay clean. Domains that never send email should go straight top=reject, together withv=spf1 -alland a null MX. - Publishing the record on the domain itself instead of at
_dmarc., or publishing two records. - Staying on
p=noneforever. - A weaker
sp=nonethat leaves every subdomain open to spoofing. - Sending
ruareports to an address on another domain without that domain's authorization record (example.com._report._dmarc.reports.example.net), so receivers drop the reports.
Common DMARC mistakes
How DnsGuard scores DMARC (30 of 100 points)
p=reject 22, p=quarantine 18, p=none 7; plus 3 if an enforcing policy applies to 100% of mail, plus 5 for a rua report address, minus 2 if sp is weaker than p. A record with syntax errors is capped at 3. Subdomains without their own record are scored on the organizational domain's record and its sp.
Check your domain now
Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.
More guides: SPF · DKIM · BIMI · MTA-STS & TLS-RPT