E-Mail-Authentifizierung & DMARC12 min read4 sections

DMARC Deep Dive

Complete DMARC guide: policies, alignment modes, subdomain handling, and the path from monitoring to enforcement.

01

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the keystone protocol that ties SPF and DKIM together with a domain-level policy. Defined in RFC 7489, DMARC solves a critical gap: SPF and DKIM alone don't protect the visible "From:" address that users see.

DMARC adds three essential capabilities:

  1. Alignment: Ensures the domain in the visible From: header matches the domain authenticated by SPF and/or DKIM.
  2. Policy: Tells receiving servers what to do with emails that fail authentication (none/quarantine/reject).
  3. Reporting: Provides visibility into who is sending email using your domain via Aggregate und Forensic Reports.
02

DMARC Record Syntax

DMARC is published as a DNS TXT record at _dmarc.example.com.

Complete Tag Reference

TagRequiredDescriptionValuesDefault
vYesVersionDMARC1—
pYesPolicy for domainnone, quarantine, reject—
spNoPolicy for subdomainsnone, quarantine, rejectSame as p
ruaNo*Aggregate Report recipientsmailto:dmarc@example.comNone
rufNoForensic Report recipientsmailto:forensic@example.comNone
adkimNoDKIM Alignment moder (relaxed), s (strict)r
aspfNoSPF Alignment moder (relaxed), s (strict)r
pctNoPercentage of emails to apply policy to0-100100
riNoReporting interval (seconds)e.g., 8640086400 (24h)
foNoForensic Report options0, 1, d, s0

* rua is technically optional but strongly recommended — without it, you get no visibility.

Example Records

# Monitoring mode (start here)
v=DMARC1; p=none; rua=mailto:dmarc@example.com; ruf=mailto:forensic@example.com

# Quarantine mode (next step)
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com; adkim=r; aspf=r

# Full enforcement
v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s; pct=100
03

DMARC Alignment Explained

Alignment is DMARC's most important concept. It ensures that the domain authenticated by SPF or DKIM matches the domain in the visible "From:" header.

Relaxed vs. Strict Alignment

ModeSPF AlignmentDKIM Alignment
Relaxed (default, adkim=r/aspf=r) Return-Path domain and From: domain must share the same Organizational Domain.
bounce.example.com aligns with example.com ✅
DKIM d= domain and From: domain must share the same Organizational Domain.
d=mail.example.com aligns with from@example.com ✅
Strict (adkim=s/aspf=s) Return-Path domain must exactly match the From: domain.
bounce.example.com does NOT align with example.com ❌
DKIM d= domain must exactly match the From: domain.
d=mail.example.com does NOT align with from@example.com ❌
Recommendation: Start with Relaxed Alignment during your monitoring phase. Only switch to Strict Alignment when you're confident that all legitimate senders are properly configured.

Alignment Examples

# Email From: user@example.com

# SPF Relaxed Alignment
Return-Path: bounce@example.com      → Aligned ✅ (same Organizational Domain)
Return-Path: bounce@mail.example.com → Aligned ✅ (same Organizational Domain)
Return-Path: bounce@other.com        → NOT Aligned ❌

# DKIM Relaxed Alignment
DKIM d=example.com    → Aligned ✅
DKIM d=mx.example.com → Aligned ✅ (same Organizational Domain)
DKIM d=google.com     → NOT Aligned ❌

# For DMARC to PASS: At least ONE of SPF or DKIM must both PASS and be ALIGNED
04

DMARC Policies: The Path to Enforcement

The DMARC policy (p=) tells receiving servers what to do with emails that fail authentication. The recommended approach is a gradual rollout:

Phase 1: Monitor (p=none)

  • No emails are blocked or quarantined
  • Aggregate Reports are collected to understand your email ecosystem
  • Use this phase to identify all legitimate senders and fix authentication issues
  • Duration: 2-4 weeks minimum, often 2-3 months for complex organizations

Phase 2: Quarantine (p=quarantine)

  • Failing emails are flagged as suspicious (typically moved to spam/junk)
  • Start with pct=10 to apply the policy to only 10% of failing emails
  • Gradually increase: 10% → 25% → 50% → 75% → 100%
  • Monitor reports at each stage for legitimate email being affected

Phase 3: Reject (p=reject)

  • Failing emails are silently dropped — they never reach the recipient
  • This is the strongest protection against Spoofing
  • Again, start with a low pct and gradually increase
  • Make sure ALL legitimate senders are properly authenticated before going to 100%
Critical: Jumping to p=reject without proper preparation can cause legitimate emails to be silently dropped. Always follow the phased approach and monitor reports carefully.