What it is

DMARC sits on top of SPF and DKIM. It does two jobs: it tells receivers what to do with mail that fails authentication, and it asks them to send you reports about what they saw. It lives at _dmarc.yourdomain.com as a TXT record.

A working record: v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com

The three policies

p=none enforces nothing. It monitors and reports, which is the correct place to start and the wrong place to stop. Plenty of domains have sat on p=none for years while their owners believed they were protected.

p=quarantine sends failing mail to spam. p=reject refuses it outright. Reject is the goal, and you get there by reading reports at none until you are confident every legitimate sender passes.

What changed in 2026

DMARC was rewritten in May 2026. RFC 9989 replaced RFC 7489, and three things moved: the pct tag is gone, np (non-existent subdomain policy) and t (testing) are new, and the Public Suffix List is no longer used for organisational domain discovery. Records written before that are not automatically broken, but several once-common patterns in them now are.

Is it mandatory?

For bulk senders to Google, Yahoo and Microsoft, effectively yes — a DMARC record is required and p=none technically satisfies it. For cold email you want to go further, because the point is protecting the domain rather than passing a check.

The record, tag by tag

DMARC is one TXT record at _dmarc.yourdomain.com. A complete record for a sending domain looks like v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@yourdomain.com; adkim=r; aspf=r; fo=1.

  • p= — policy for the domain: none, quarantine or reject. The only tag that matters to receivers.
  • sp= — policy for subdomains. Without it, subdomains inherit p=. Set it explicitly so a forgotten subdomain is not a loophole.
  • rua= — where daily aggregate reports go. A record without one is a policy you cannot see working.
  • ruf= — forensic reports with message samples. Few receivers send them; harmless to include, do not rely on it.
  • adkim= / aspf= — relaxed (r) or strict (s) alignment. Relaxed lets mail.acme.com align with acme.com; strict requires an exact match. Relaxed is right for almost everyone.
  • fo= — when to send a forensic report. 1 means on any failure, which is the useful setting if you have ruf.

The pct= tag was removed from the standard in 2026; some receivers still honour it, none require it. Leave it out of new records. The DMARC generator builds a correct record from a few choices.

Reading an aggregate report

Every day, each receiver that saw your mail sends one XML file to your rua address. Inside, for each source IP that sent as your domain: how many messages, whether SPF passed, whether DKIM passed, whether each aligned, and what the receiver did. Raw, it is unreadable; the report parser turns it into a table.

Three things to look for. Sources you recognise that fail alignment — your own tool signing with the wrong domain, a CRM sending as you with no DKIM. Sources you do not recognise at all — either a service someone set up without telling you, or spoofing, and the volume usually tells you which. And the ratio of aligned to unaligned mail over time, which is the number that says whether you can move the policy up.

Moving a sending fleet to enforcement

Start every new domain at p=none with rua set, before any mail is sent. Two weeks of reports with every source aligned is the signal to move to p=quarantine. Two more clean weeks, p=reject. On a cold email fleet where every domain sends through one provider and one tool, the whole path takes a month and can be done for a wave of domains at once — the policy simulator shows what a given policy would have done to last week's reports before you publish it.

The mistake is stopping at none. Google and Microsoft accept it for the bulk-sender rules, so it feels done. But an enforcing policy is the only thing that stops anyone else sending as your domain, and receivers read p=reject as a domain whose owner is paying attention. The step-by-step post covers the third-party senders and subdomains that make this harder on a main company domain than on a sending fleet.

Check yours

These run free in your browser. Nothing you type reaches a server.

Common questions

Can I go straight to p=reject?

You can, and you may silently kill legitimate mail from a service you forgot about. Start at none, read the aggregate reports for a few weeks, fix what is failing, then move up through quarantine.

What are rua and ruf?

rua receives aggregate reports — daily XML summaries of what receivers saw, and the useful one. ruf receives forensic reports on individual failures, which most large receivers no longer send for privacy reasons.

Why is my mail failing DMARC when SPF and DKIM pass?

Alignment. DMARC requires that the domain SPF or DKIM passed for matches the domain in the visible From header. Both can pass without either aligning.

Do I need a different DMARC record on every sending domain?

Every domain needs its own record at its own _dmarc name, but the content can be identical across a fleet, including the rua address. A single reporting mailbox receiving reports for forty domains is normal; the parser separates them by domain. Do not try to share one record with a CNAME — some receivers handle it, some do not, and the failure is silent.

Where should DMARC reports go on a large fleet?

To one dedicated mailbox or a reporting service, not to a person's inbox — a forty-domain fleet produces hundreds of XML files a week. If the rua address is on a different domain from the one being reported on, that domain must publish an authorisation record at yourdomain.com._report._dmarc.reportingdomain.com, or receivers will not send. The rua authorization checker tests exactly this.

Next

Related concepts

How I measure this on client accounts

Everything above is diagnosis. To confirm a fix worked you need placement data — seed accounts across the major providers, plus the DMARC aggregate reports read as a trend rather than a wall of XML. GlockApps is what I run for both.

See GlockApps →Affiliate link — it costs you nothing and help keep these tools free. Everything I use →
When it is broken

If this is the thing going wrong

The pages explain it. If you would rather it was simply fixed, that is the work I do.

← All conceptsEmail authenticationReputationDeliveryInfrastructureBook a call →
Back to top↑