DMARC Policy Setup: From p=none to p=reject Safely
How to set up a DMARC policy: record syntax, every tag explained, reading aggregate reports, and a safe rollout from p=none to quarantine to reject.
On this page
A DMARC policy is a TXT record at _dmarc.yourdomain that tells receiving servers what to do with mail that fails SPF and DKIM alignment: p=none (monitor), p=quarantine (send to spam) or p=reject (refuse). Set it up by publishing p=none with a report address, fixing every legitimate sender the reports reveal, then tightening to quarantine and reject over several weeks.
What a DMARC policy controls
DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) sits on top of SPF and DKIM. A message passes DMARC when SPF or DKIM passes and the authenticated domain aligns with the domain in the visible From: header. When a message fails, your published policy is the instruction receivers apply.
DMARC gives you two things: protection, because once you reach p=reject, criminals can no longer send mail that shows your exact domain in the From line; and visibility, because receivers send you daily reports listing every server that sent mail using your domain. If SPF and DKIM are still new to you, read SPF, DKIM and DMARC explained first.
Since 2024 Gmail and Yahoo require bulk senders to publish a DMARC record (at least p=none), so even a monitoring-only record is no longer optional for many businesses.
Anatomy of a DMARC record
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; sp=quarantine; pct=100; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r; fo=1"| Tag | Required | Values | What it does |
|---|---|---|---|
v | Yes | DMARC1 | Version; must be first. |
p | Yes | none, quarantine, reject | Policy for the domain itself. |
sp | No | same as p | Policy for subdomains; defaults to p. |
pct | No | 0–100 | Percentage of failing mail the policy applies to; default 100. |
rua | No | mailto: URIs | Where to send daily aggregate reports. |
ruf | No | mailto: URIs | Where to send per-message failure reports (rarely sent by large providers). |
adkim | No | r or s | DKIM alignment: relaxed (default) or strict. |
aspf | No | r or s | SPF alignment: relaxed (default) or strict. |
fo | No | 0, 1, d, s | When failure reports are generated. |
ri | No | seconds | Requested report interval; default 86400 (daily). |
A few precise rules worth knowing:
- There must be exactly one DMARC record at
_dmarc.example.com. Two records mean receivers ignore DMARC. - If a subdomain such as
mail.example.comhas no DMARC record of its own, receivers fall back to the organisational domain's record and applysp=. - If the
ruaaddress is on a different domain from the one being reported on, that domain must publish an authorisation record (example.com._report._dmarc.reports.example) or receivers will not send reports. Report services handle this for you.
The three policies
**p=none — monitor.** Receivers do nothing different with failing mail but send you reports. Use it to discover your senders. It offers no protection on its own.
**p=quarantine — treat as suspicious.** Failing mail is typically delivered to the spam or junk folder. This is the safety net stage: if a legitimate sender was missed, its mail is delayed, not lost.
**p=reject — refuse.** Receivers reject failing mail during the SMTP conversation. This is the goal: spoofed mail using your exact domain never reaches inboxes.
A safe rollout plan
Moving too fast is the most common DMARC mistake: a billing system or website form that was never authenticated suddenly loses its mail. This schedule fits most small and mid-sized businesses.
- **Weeks 1–4:
p=nonewith reports.**
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comCollect at least two to four weeks of aggregate reports so that monthly senders (invoices, payroll) show up.
- Fix every legitimate source. For each sender in the reports that fails, either add it to your SPF record or, better, configure it to sign with DKIM using your domain (how to set up DKIM). Sources you don't recognise are either forgotten tools or spoofing.
- Weeks 5–8: quarantine, gradually.
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.comWith pct=25, the quarantine policy applies to a quarter of failing mail; receivers handle the rest as if the policy were the next one down (none). Raise to 50, then 100, while watching reports and asking colleagues whether anything went missing.
- Weeks 9+: reject.
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.comYou can step pct again (p=reject; pct=25 means the remainder is quarantined). Once at p=reject with pct=100, keep reading reports: a new marketing tool next year will need adding before it sends.
Reading DMARC aggregate reports
Aggregate (rua) reports are XML files, typically sent once a day by each large mailbox provider. Each one lists source IP addresses, message counts, the SPF and DKIM results, whether they aligned, and the policy applied. Raw XML is hard to read, so most people use a dashboard that groups sources by sender.
When you review them, sort sources into three groups:
- Passing and aligned — your mailbox provider and correctly configured tools. Nothing to do.
- Legitimate but failing — for example, your CRM sending with its own domain in DKIM, or a new server not in SPF. Fix these before tightening.
- Unknown and failing — usually spoofing or spam using your domain. These are what
p=rejectwill block.
Forwarded mail often appears as failing SPF but passing DKIM; that is normal and still passes DMARC.
Special cases
- Subdomains for bulk mail. If newsletters go out from
news.example.com, give it its own SPF, DKIM and, if needed, its own_dmarc.news.example.comrecord so you can tighten the main domain independently. - Parked domains that never send mail. Lock them down completely:
v=spf1 -allas SPF,v=DMARC1; p=reject;as DMARC and a null MX (MX 0 ., RFC 7505). See MX records explained. - Mailing lists. Lists that change the subject or add footers break DKIM. Many lists now rewrite the From address to their own domain to avoid DMARC failures, and receivers may use ARC headers from trusted forwarders.
Strict DMARC enforcement is one of the clearest ways to stop invoice fraud using your own name, but it does not cover lookalike domains; see why emails go to spam for the deliverability side, and inbox-level anti-phishing settings for lookalikes.
DMARC with Zomail
Zomail's domain page shows the DMARC record to publish, with an rua address already pointing to Zomail's report collection; the exact value is on your domain page. The DMARC reports dashboard then shows, for the last 30 days, how much mail was reported, the pass rate, the top sending sources, the failing sources and recommendations of what to fix, so you know when it is safe to move to quarantine and reject. The getting started guide covers the DNS steps, and plans are on the pricing page.
FAQ
What DMARC policy should I start with?
Start with p=none and a rua report address. It changes nothing for your mail flow but shows you every source sending as your domain. After two to four weeks, once legitimate senders pass, move to p=quarantine and then p=reject.
Is p=none enough to protect my domain?
No. p=none only monitors; spoofed mail is delivered as if DMARC did not exist. It satisfies Gmail and Yahoo's minimum requirement for bulk senders, but real protection against exact-domain spoofing starts at quarantine and is complete at reject.
What does pct mean in a DMARC record?
pct sets the percentage of failing messages that the policy applies to. With p=quarantine; pct=25, a quarter of failing mail is quarantined and the rest is treated as p=none. It lets you tighten gradually. The default is 100.
Will p=reject block my legitimate email?
Only if a legitimate sender is not authenticated with SPF or DKIM aligned to your domain. That is why you read reports at p=none first and fix every source. Mail sent through your properly configured mailbox provider is unaffected.
How often do DMARC reports arrive?
Aggregate reports usually arrive once a day from each large provider that received mail from your domain. It is normal to see no reports for the first day or two after publishing the record.