DMARC¶
Use this page to configure or review DMARC for a domain. Keep current DNS records handy and check the result after publishing changes.
Do not start with reject
A strict DMARC policy can block legitimate mail if SPF or DKIM is incomplete. Start with monitoring, review reports, then move to enforcement gradually.
DMARC Record Builder¶
Use the builder to draft a record, then publish it as a TXT record at
_dmarc.example.com, replacing example.com with your domain.
Before You Publish DMARC¶
-
Check SPF
Make sure every service that sends mail for the domain is included in SPF.
-
Check DKIM
Confirm DKIM is enabled and the public DKIM TXT record is published.
-
Check current DNS
Verify the domain's SPF, DKIM, and DMARC records before tightening policy.
Recommended Rollout¶
| Phase | Policy | Purpose |
|---|---|---|
| Monitor | p=none |
Collect reports without changing mail delivery. |
| Quarantine | p=quarantine; pct=25 |
Send a small percentage of failing mail to spam or quarantine. |
| Increase | p=quarantine; pct=100 |
Apply quarantine to all mail that fails DMARC. |
| Reject | p=reject; pct=100 |
Block mail that fails DMARC after reports confirm legitimate mail passes. |
Increase enforcement only after reports show that legitimate senders pass SPF or DKIM alignment.
Example Records¶
Start with monitoring:
v=DMARC1; p=none; rua=mailto:dmarc@example.com; pct=100; fo=1
Move to quarantine after reports look clean:
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com; fo=1
Move to reject only after legitimate mail is passing:
v=DMARC1; p=reject; pct=100; rua=mailto:dmarc@example.com; fo=1
Use a real reporting mailbox
Replace dmarc@example.com with a mailbox or reporting service that can
receive DMARC aggregate reports. DMARC reports can be noisy and XML-heavy.
DMARC Tags¶
| Tag | Meaning | Common values |
|---|---|---|
v |
Record version. | DMARC1 |
p |
Policy for the root domain. | none, quarantine, reject |
sp |
Policy for subdomains. | none, quarantine, reject |
rua |
Aggregate report destination. | mailto:dmarc@example.com |
ruf |
Forensic report destination. | Usually omitted unless you know you need it. |
pct |
Percentage of failing mail affected by policy. | 25, 50, 75, 100 |
aspf |
SPF alignment mode. | r relaxed, s strict |
adkim |
DKIM alignment mode. | r relaxed, s strict |
fo |
Failure report options. | 0, 1, d, s |
Alignment¶
DMARC passes when either SPF or DKIM passes and aligns with the visible From
domain.
| Alignment mode | Behavior |
|---|---|
| Relaxed | A subdomain can align with the root domain. This is the usual default. |
| Strict | The authenticated domain must exactly match the visible From domain. |
Strict alignment can be useful, but it is easier to break when third-party services send mail for the domain.
Related Guides¶
-
SPF
-
DKIM
-
DNS checker