Email

What is DMARC?

Definition

DMARC tells receivers what to do with messages that fail SPF and DKIM, and where to send aggregate reports. Start at p=none and read the reports for a fortnight before tightening. Going straight to p=reject on an established domain reliably breaks systems you had forgotten were sending mail.

Why DMARC matters

Start at p=none and read the reports for a fortnight before tightening. Going straight to p=reject on an established domain reliably breaks systems you had forgotten were sending mail.

DMARC in practice

When running DMARC, you start by publishing a TXT record with p=none. Then you read the aggregate reports it generates. Those reports tell you which of your mail streams fail SPF or DKIM. You fix those sources, then tighten the policy. The cost of getting it wrong is silent delivery loss: messages that get rejected or quarantined and no one tells you. You check the reports regularly, not once.

What people get wrong about DMARC

The common mistake is treating DMARC as a spam filter, so people go straight to p=reject on a domain that has never had DMARC. They break mail sent by old marketing tools, CRM systems, or printers they forgot. The correction: start at p=none, monitor reports for at least two weeks, then tighten only after you have confirmed all legitimate senders pass.

DMARC — common questions

Do I need both SPF and DKIM?

DMARC needs at least one of SPF or DKIM to pass, and alignment with your domain. Having both is safer because a forwarding server can break SPF, but DKIM survives forwarding. So run both and align both to be resilient.

What does p=none do?

p=none tells receivers to take no action on failures, but still send you aggregate reports. It is the safe starting point. You learn where your mail goes wrong before you enforce anything. It does not protect users, but it protects you from breaking delivery.

More from email

SPF
SPF is a DNS record listing which servers are authorised to send mail for a domain.
DKIM
DKIM cryptographically signs outgoing messages so a receiver can verify the domain and that the content was not altered in transit.