DMARC

Use this page to configure or review DMARC for a domain. Keep current DNS records handy and check the result after publishing changes.

Do not start with reject

A strict DMARC policy can block legitimate mail if SPF or DKIM is incomplete. Start with monitoring, review reports, then move to enforcement gradually.

DMARC Record Builder

Use the builder to draft a record, then publish it as a TXT record at _dmarc.example.com, replacing example.com with your domain.

Before You Publish DMARC

  • Check SPF


    Make sure every service that sends mail for the domain is included in SPF.

    Review SPF

  • Check DKIM


    Confirm DKIM is enabled and the public DKIM TXT record is published.

    Review DKIM

  • Check current DNS


    Verify the domain's SPF, DKIM, and DMARC records before tightening policy.

    Open DNS checker

Phase Policy Purpose
Monitor p=none Collect reports without changing mail delivery.
Quarantine p=quarantine; pct=25 Send a small percentage of failing mail to spam or quarantine.
Increase p=quarantine; pct=100 Apply quarantine to all mail that fails DMARC.
Reject p=reject; pct=100 Block mail that fails DMARC after reports confirm legitimate mail passes.

Increase enforcement only after reports show that legitimate senders pass SPF or DKIM alignment.

Example Records

Start with monitoring:

v=DMARC1; p=none; rua=mailto:dmarc@example.com; pct=100; fo=1

Move to quarantine after reports look clean:

v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com; fo=1

Move to reject only after legitimate mail is passing:

v=DMARC1; p=reject; pct=100; rua=mailto:dmarc@example.com; fo=1

Use a real reporting mailbox

Replace dmarc@example.com with a mailbox or reporting service that can receive DMARC aggregate reports. DMARC reports can be noisy and XML-heavy.

DMARC Tags

Tag Meaning Common values
v Record version. DMARC1
p Policy for the root domain. none, quarantine, reject
sp Policy for subdomains. none, quarantine, reject
rua Aggregate report destination. mailto:dmarc@example.com
ruf Forensic report destination. Usually omitted unless you know you need it.
pct Percentage of failing mail affected by policy. 25, 50, 75, 100
aspf SPF alignment mode. r relaxed, s strict
adkim DKIM alignment mode. r relaxed, s strict
fo Failure report options. 0, 1, d, s

Alignment

DMARC passes when either SPF or DKIM passes and aligns with the visible From domain.

Alignment mode Behavior
Relaxed A subdomain can align with the root domain. This is the usual default.
Strict The authenticated domain must exactly match the visible From domain.

Strict alignment can be useful, but it is easier to break when third-party services send mail for the domain.