DMARC at p=none: how to move to quarantine and reject
p=none only monitors, so spoofed email is still delivered. How to read the reports, fix your senders, and step up to quarantine and reject safely.
By the Domain Health Hub team · Updated
- p=none asks receivers to deliver email that fails DMARC as normal. It's for monitoring, not protection.
- Use the reports to make every genuine sender pass SPF or DKIM, aligned with the From domain.
- Then move to p=quarantine, and to p=reject after a few clean weeks. Keep pct at 100, or leave it out.
What it means
The DMARC record says p=none. Receivers send you reports, but email that fails DMARC, including forgeries of your From address, is delivered as if there were no policy. It's the right place to start and the wrong place to stay: the protection only begins at quarantine (treat failures as suspicious, usually the spam folder) and is complete at reject (refuse them).
And pct below 100
pct= applies the policy to only part of the failing email. Under section 6.6.4 of RFC 7489, the rest gets the next policy down: reject becomes quarantine, quarantine becomes none. It's useful for a cautious first step, but a domain left at pct=10 lets nine in ten forgeries through.
How to confirm it
How to fix it
- Make sure reports are arriving (see rua=) and give them two weeks or more, to include monthly senders such as invoicing systems.
- List every source. For each genuine one, set up DKIM signing with your own domain, and SPF with a return path on your domain. Either one passing and aligned is enough for DMARC.
- When every known source is passing, change the record to
p=quarantine. Optionally usepct=25, then 50, then 100 over a couple of weeks. - After a few clean weeks at quarantine, change it to
p=reject.
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com
The email test is a quick way to check a single sender before you tighten the policy: send one message and see whether SPF and DKIM pass and line up with the From address.
Cloudflare DNS
- Open the domain in the Cloudflare dashboard and go to DNS, then Records.
- Add a record of type TXT with the name
_dmarc. Cloudflare adds the domain for you. - Paste the record as the content and save.
Microsoft 365
Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.
Google Workspace
The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.
Questions
What if something breaks after moving to reject?
Drop back to quarantine while you fix the sender. The reports show which source started failing and on which day.
Do I need sp= as well?
Only if subdomains should get a different policy. Without sp=, subdomains inherit p=.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.