DnsGuard › Guides › DMARC

DMARC explained

DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) ties SPF and DKIM to the address people actually see in the From: header, tells receivers what to do with mail that fails, and asks them to send you reports. It's what actually stops other people from sending mail that looks like it comes from your domain.

What a DMARC record looks like

_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; pct=100; adkim=r; aspf=r"
TagMeaning
v=DMARC1Required, and must come first.
p=Required policy for failing mail: none (monitor only), quarantine (spam folder) or reject (refuse it).
sp=Policy for subdomains. Defaults to p.
rua=Where receivers send daily aggregate reports (mailto: addresses).
ruf=Where to send per-message failure reports. Few receivers send them.
pct=Percentage of failing mail the policy applies to (default 100). Useful during rollout.
adkim= / aspf=Alignment mode: r relaxed (default; subdomains of the same organizational domain match) or s strict (exact match).

Alignment: why SPF and DKIM passing isn't enough

A message passes DMARC when either SPF passes for a domain that aligns with the From: domain, or a DKIM signature passes with a d= domain that aligns with it. A newsletter sent through a third-party tool might pass SPF for the tool's own bounce domain and still fail DMARC, because that domain isn't yours. The fix is to set up the tool's custom return-path or DKIM domain on your own domain.

p=none vs p=quarantine vs p=reject

A safe rollout plan

  1. Publish p=none with a rua= address and read the aggregate reports for two to four weeks.
  2. Fix every legitimate sender that fails: add it to SPF, turn on DKIM signing with your domain, or move it to a subdomain.
  3. Move to p=quarantine, optionally with pct=25 and then 50 and 100.
  4. Move to p=reject once reports stay clean. Domains that never send email should go straight to p=reject, together with v=spf1 -all and a null MX.
  5. Common DMARC mistakes

    How DnsGuard scores DMARC (30 of 100 points)

    p=reject 22, p=quarantine 18, p=none 7; plus 3 if an enforcing policy applies to 100% of mail, plus 5 for a rua report address, minus 2 if sp is weaker than p. A record with syntax errors is capped at 3. Subdomains without their own record are scored on the organizational domain's record and its sp.

    Check your domain now

    Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.

    More guides: SPF · DKIM · BIMI · MTA-STS & TLS-RPT