Skip to content

What is DMARC? A plain-English guide for agencies

What DMARC does, how it works with SPF and DKIM, what none, quarantine and reject mean, and how to move a client to reject safely.

By the Domain Health Hub team · Updated

In short
  • DMARC is a DNS record that tells receiving mail servers what to do with email that claims to be from a domain but fails SPF and DKIM.
  • It has three policies: none (report only), quarantine (send to spam) and reject (refuse).
  • Start at none, read the reports, fix every real sender, then tighten step by step.

What DMARC does

Anyone can send an email with your client's domain in the From address. Without DMARC, the receiving server has to guess whether it's genuine. DMARC (Domain-based Message Authentication, Reporting and Conformance) lets the domain owner publish a policy that answers the question, and ask for daily reports on who is sending as them.

For a small business that means fewer convincing phishing emails in its customers' inboxes, and better delivery for its own mail.

How it works with SPF and DKIM

DMARC doesn't check anything itself. It builds on two older checks and adds one rule: at least one of them must pass, and match the domain in the From address. That match is called alignment.

  • SPF asks: was this sent from a server the domain lists as allowed?
  • DKIM asks: is it signed with a key the domain publishes?
  • Alignment asks: is the domain that passed the same as the one the reader sees in From?

If SPF or DKIM passes and aligns, the message passes DMARC. If neither does, the domain's policy decides what happens to it.

What a DMARC record looks like

It's a single TXT record at _dmarc in front of the domain:

_dmarc.example.com TXT
v=DMARC1; p=quarantine; pct=100; rua=mailto:reports@example.com
v=DMARC1
Required, and must come first.
p=
Required. The policy: none, quarantine or reject.
sp=
Optional policy for subdomains. Uses p= if left out.
pct=
Optional share of failing mail the policy applies to, 0 to 100. Defaults to 100.
rua=
Where to send daily aggregate reports. Strongly recommended.
adkim=
DKIM alignment: r for relaxed (the default) or s for strict.
aspf=
SPF alignment: r for relaxed (the default) or s for strict.

none, quarantine and reject

p=none
Report only. Nothing changes for failing mail; use it to find every sender.
p=quarantine
Failing mail goes to the junk folder. A safe middle step.
p=reject
Failing mail is refused. Full protection for the domain.

Moving a client to reject safely

  1. Publish p=none with a rua address. Nothing changes for delivery, but reports start arriving.
  2. List every sender. Use the reports to find each service sending as the domain: the mailbox provider, newsletters, invoicing, the website's contact form.
  3. Fix each one. Add it to SPF or, better, set up DKIM signing with the domain's own key, until each passes and aligns.
  4. Move to quarantine once real mail passes consistently for a couple of weeks. Use pct to phase it in if you want to be extra careful.
  5. Move to reject when the reports show only unknown senders failing. Keep watching them for new services.

DMARC reports

The rua address receives an aggregate report from each large mailbox provider, usually once a day. Each lists the servers that sent mail as the domain, how many messages, and whether they passed. They arrive as zipped XML, which is why most people use a tool to read them. Domain Health Hub gives every domain its own reporting address and turns the reports into a list of senders.

There's also a ruf tag for forensic reports: copies of individual failing messages. Few providers still send them and they can contain personal data, so we recommend leaving it out.

Common mistakes

  • Publishing two DMARC records. Receivers then ignore both.
  • Jumping straight to reject before a newsletter or invoicing tool passes.
  • Leaving a domain at none for years, which reports but protects nothing.
  • Forgetting domains that never send email. Give them p=reject straight away.

Questions

Do Google and Yahoo require DMARC?

Since February 2024, anyone sending more than 5,000 messages a day to Gmail addresses must publish a DMARC record, even at p=none, and Yahoo has similar rules. Smaller senders benefit too: authenticated mail is simply trusted more.

Will DMARC stop spam arriving in my client's inbox?

No. DMARC protects a domain from being impersonated in other people's inboxes. Filtering the spam a client receives is a separate job.

Does a domain need DMARC if it never sends email?

Yes, and it's the easiest case: publish p=reject and an SPF record of v=spf1 -all, so nobody can send as it.

How long until reports arrive?

Usually within a day or two of publishing a record with a rua address.

Watch every client's domains, every day.

Reports read for you, and a monthly report card your clients will understand.

Start 28-day free trial