Rolling out DMARC without blocking your own mail
- Week 0: publish
p=nonewith aruaaddress. Nothing changes for delivery yet. - Weeks 1–4: read the aggregate reports. Every service that sends as your domain shows up there. Make each one pass SPF or DKIM with your domain — the SPF Checker and DKIM Checker help here.
- Then: switch to
p=quarantine. If you're cautious, usepct=25first and raise it. - Finally: move to
p=rejectonce reports show only failures you don't recognize.
What each tag does
p— what receivers do with mail that fails DMARC.sp— the same for subdomains; defaults top.rua— where daily aggregate reports are sent.pct— the share of failing mail the policy applies to.adkim/aspf— relaxed alignment accepts subdomains of your From domain; strict requires an exact match.
Frequently asked questions
Start with p=none and a rua address. Read the reports for a few weeks, fix any legitimate service that fails, then move to quarantine and finally reject.
Create a TXT record with the host _dmarc (the full name is _dmarc.yourdomain.com) and paste the generated value. A domain must have only one DMARC record.
Yes, but the receiving domain must publish an authorization record (yourdomain.com._report._dmarc.otherdomain.com). Most DMARC reporting services set this up for you.
Usually not. Few large mailbox providers send them, and they can contain personal data. Aggregate reports (rua) are what you need.