Getting Started

What Is DMARC?

DMARC is a DNS record that tells receiving mail servers what to do when someone sends email pretending to be from your domain. It builds on SPF and DKIM to give you real enforcement over who can send as you.

5 min read · Updated June 2026

The problem DMARC solves

Without DMARC, anyone can send email that claims to be from billing@yourcompany.com. Receiving mail servers have no way to know whether that message came from you or from a threat actor running a phishing campaign.

DMARC gives you a way to say: here's my authentication policy, and here's what to do with mail that fails it.

What DMARC actually does

DMARC is a TXT record you publish in DNS at _dmarc.yourdomain.com. It does three things:

  1. Declares a policy — none, quarantine, or reject — for messages that fail authentication.
  2. Requests reports — receiving servers send you XML reports about what they're seeing.
  3. Enforces alignment — it checks that the authenticated sender domain matches the visible From: address.

A basic DMARC record looks like this:

_dmarc.yourdomain.com TXT "v=DMARC1; p=none; rua=mailto:reports@yourdomain.com"

At p=none, DMARC is watching but not yet enforcing. It will still send you reports.

How SPF, DKIM, and DMARC relate

DMARC doesn't authenticate on its own — it layers on top of SPF and DKIM.

Protocol What it does
SPF Lists which mail servers are allowed to send for your domain
DKIM Signs each outgoing message with a cryptographic key
DMARC Checks alignment and tells receivers what to do when neither SPF nor DKIM aligns

DMARC passes when at least one of SPF or DKIM passes and the authenticated domain aligns with the visible From: address. If neither aligns, DMARC fails and your policy applies.

The three policy levels

p=none — Do nothing with failing mail. Just report. This is where you start.

p=quarantine — Route failing mail to spam or junk. Most receivers honor this.

p=reject — Reject failing mail outright. The goal for most domains.

You always start at p=none and work toward p=reject. Jumping straight to reject without knowing your mail sources is how you break legitimate email.

Why Google and Yahoo require it

Since early 2024, Google and Yahoo require bulk senders to have SPF, DKIM, and a DMARC record at minimum. The standard for DMARC is currently RFC 9989, which replaced RFC 7489 in 2024.

Even if you're not a bulk sender, a domain without DMARC is a domain that anyone can impersonate. That's a risk for your customers, your brand, and your email deliverability.

What to do next

If you don't have DMARC set up yet, the right path is:

  1. Set up SPF
  2. Set up DKIM
  3. Publish DMARC at p=none and collect reports
  4. Follow the enforcement path to reach reject

dmarcdemon collects and parses those aggregate reports automatically, giving you a readable view of every sender, pass rate, and failure source.

Monitor your DMARC alignment. dmarcdemon collects aggregate reports from every receiving mail server and shows you exactly which senders are passing, which are failing, and what to fix.
Start free — 2 domains, no card