Set up a DMARC policy
Add a DMARC record to protect your domain from spoofing and control how failing mail is handled.
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do when a message claiming to be from your domain fails SPF and DKIM checks. It also asks those servers to send you reports, so you can see who is sending on your behalf before you enforce a strict policy.
Before you begin
- Confirm that both SPF and DKIM are already published and passing for your sending domain — DMARC relies on them.
- Make sure you can create and edit TXT records in your domain's DNS (or have access to whoever manages DNS).
- Decide on a monitoring mailbox to receive aggregate reports (for example, an inbox or a third-party DMARC reporting service).
- Have your sending domain confirmed with your account team (confirm the exact steps in your account).
Steps
- Choose a starting policy of
p=none. This monitors traffic without affecting delivery, so you can watch reports safely. - Build a TXT record for the host
_dmarc.yourdomain.com. A typical starting value looks like:v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1 - Publish the TXT record in your DNS and allow time for it to propagate (often up to a few hours).
- Collect aggregate reports for a few weeks. Verify that all legitimate mail — including your Broadcasts — passes DKIM and SPF alignment.
- When your legitimate traffic is clean, tighten the policy in stages: move to
p=quarantine, then top=reject. Optionally addpct=to roll out enforcement to a percentage of mail first.
Result
Sending servers now honour your DMARC policy, and unauthenticated mail spoofing your domain is quarantined or rejected. You receive regular reports showing authentication results for messages using your domain.
Related
Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.