SPF and DKIM can tell a receiving server that a message was sent by an authorised server or signed by a particular domain. Neither, on its own, says anything about the address in the From line that your customers actually read, and neither tells the receiver what to do when checks fail. DMARC fills both gaps. Your DMARC policy is a published instruction: "if mail claims to be from my domain and fails authentication, monitor it, put it in spam, or reject it".
What DMARC adds: alignment
DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) passes a message only if at least one of these is true:
- SPF passes and the domain SPF checked (the envelope sender) aligns with the From domain.
- DKIM passes and the signing domain (
d=) aligns with the From domain.
"Aligns" means matches. In relaxed alignment, the default, the organisational domains must match, so mail.example.com aligns with example.com. In strict alignment they must be identical. This is what stops a spammer from passing SPF with their own domain in the envelope while putting yours in the From line.
A common surprise: a newsletter platform sending as you may pass SPF and DKIM for its domain, yet fail DMARC for yours, because neither aligns. Setting up custom DKIM for that platform fixes it.
The DMARC record
DMARC is a TXT record at _dmarc.yourdomain:
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; adkim=r; aspf=r"
| Tag | Meaning | Values |
|---|---|---|
v | Version, must come first | DMARC1 |
p | Policy for the domain | none, quarantine, reject |
sp | Policy for subdomains (defaults to p) | Same as p |
rua | Where to send daily aggregate reports | mailto: address(es) |
ruf | Where to send failure (forensic) reports; few receivers send them | mailto: address(es) |
pct | Percentage of failing mail the policy applies to | 0–100, default 100 |
adkim / aspf | Alignment mode for DKIM / SPF | r (relaxed) or s (strict) |
The three DMARC policies
p=none: monitor only
Receivers deliver failing mail as they normally would, and send you reports. It provides visibility, not protection: spoofed mail using your domain is not blocked by your DMARC record. It is the right place to start, and the minimum that Gmail and Yahoo now require of bulk senders, but it is not a place to stay indefinitely.
p=quarantine: treat as suspicious
Receivers are asked to treat failing mail as suspicious, which in practice usually means delivering it to the spam or junk folder. Legitimate mail you forgot to authenticate is still recoverable by the recipient, which makes quarantine a useful intermediate step.
p=reject: refuse it
Receivers are asked to reject failing mail during the SMTP conversation, so it never reaches the recipient at all. This gives the strongest protection against exact-domain spoofing. It also means any legitimate source you missed will have its messages bounced, so get there carefully.
Receivers treat your policy as a strong request rather than an absolute command. They may apply local judgement, for example when they can tell mail was forwarded through a mailing list.
A safe path from none to reject
- Publish
p=nonewith aruaaddress. Check the record with the SPF, DKIM and DMARC checker. - Read the aggregate reports for a few weeks. Identify every source sending as your domain: your mailbox provider, CRM, billing system, support desk, website forms.
- Fix each legitimate source so that it passes with alignment, preferably via DKIM signing with your domain.
- Move to
p=quarantine, optionally starting withpct=25and increasing it, while watching reports and listening for complaints of missing mail. - Move to
p=rejectonce reports show only unauthorised sources failing. - Keep monitoring. New tools get adopted; make DMARC alignment part of onboarding any service that sends email.
How long this takes depends on how many systems send as your domain. A small business using one mailbox provider may get there quickly; an organisation with many departments and tools may need months.
Subdomains and domains that do not send
The sp tag controls subdomains that do not have their own DMARC record. Attackers often use made-up subdomains such as billing.example.com, so do not leave sp=none once the main domain is enforced. For parked domains that never send mail, the strongest setup is:
example.net. TXT "v=spf1 -all"
_dmarc.example.net. TXT "v=DMARC1; p=reject; sp=reject"
Reporting to a third-party address
If your rua address is on a different domain, for example a DMARC reporting service, that domain must publish a record authorising it, such as example.com._report._dmarc.reports-provider.net containing v=DMARC1. Reputable report services set this up for you; if reports never arrive, it is the first thing to check, and a DNS lookup of that name confirms whether it exists.
Key takeaways
- DMARC passes mail only when SPF or DKIM passes and aligns with the visible From domain.
p=nonemonitors,p=quarantinesends failures to spam,p=rejectblocks them.- Start at none with reporting, fix every legitimate sender, then step up to quarantine and reject.
- Set a subdomain policy and protect non-sending domains with
p=reject.