What Is DMARC?
DMARC is a DNS record that tells receiving mail servers what to do when someone sends email pretending to be from your domain. It builds on SPF and DKIM to give you real enforcement over who can send as you.
The problem DMARC solves
Without DMARC, anyone can send email that claims to be from billing@yourcompany.com. Receiving mail servers have no way to know whether that message came from you or from a threat actor running a phishing campaign.
DMARC gives you a way to say: here's my authentication policy, and here's what to do with mail that fails it.
What DMARC actually does
DMARC is a TXT record you publish in DNS at _dmarc.yourdomain.com. It does three things:
- Declares a policy — none, quarantine, or reject — for messages that fail authentication.
- Requests reports — receiving servers send you XML reports about what they're seeing.
- Enforces alignment — it checks that the authenticated sender domain matches the visible
From:address.
A basic DMARC record looks like this:
_dmarc.yourdomain.com TXT "v=DMARC1; p=none; rua=mailto:reports@yourdomain.com"
At p=none, DMARC is watching but not yet enforcing. It will still send you reports.
How SPF, DKIM, and DMARC relate
DMARC doesn't authenticate on its own — it layers on top of SPF and DKIM.
| Protocol | What it does |
|---|---|
| SPF | Lists which mail servers are allowed to send for your domain |
| DKIM | Signs each outgoing message with a cryptographic key |
| DMARC | Checks alignment and tells receivers what to do when neither SPF nor DKIM aligns |
DMARC passes when at least one of SPF or DKIM passes and the authenticated domain aligns with the visible From: address. If neither aligns, DMARC fails and your policy applies.
The three policy levels
p=none — Do nothing with failing mail. Just report. This is where you start.
p=quarantine — Route failing mail to spam or junk. Most receivers honor this.
p=reject — Reject failing mail outright. The goal for most domains.
You always start at p=none and work toward p=reject. Jumping straight to reject without knowing your mail sources is how you break legitimate email.
Why Google and Yahoo require it
Since early 2024, Google and Yahoo require bulk senders to have SPF, DKIM, and a DMARC record at minimum. The standard for DMARC is currently RFC 9989, which replaced RFC 7489 in 2024.
Even if you're not a bulk sender, a domain without DMARC is a domain that anyone can impersonate. That's a risk for your customers, your brand, and your email deliverability.
What to do next
If you don't have DMARC set up yet, the right path is:
- Set up SPF
- Set up DKIM
- Publish DMARC at
p=noneand collect reports - Follow the enforcement path to reach reject
dmarcdemon collects and parses those aggregate reports automatically, giving you a readable view of every sender, pass rate, and failure source.