What is DMARC?
DMARC (Domain-based Message Authentication, Reporting & Conformance) is the keystone protocol that ties SPF and DKIM together with a domain-level policy. Defined in RFC 7489, DMARC solves a critical gap: SPF and DKIM alone don't protect the visible "From:" address that users see.
DMARC adds three essential capabilities:
- Alignment: Ensures the domain in the visible From: header matches the domain authenticated by SPF and/or DKIM.
- Policy: Tells receiving servers what to do with emails that fail authentication (none/quarantine/reject).
- Reporting: Provides visibility into who is sending email using your domain via Aggregate und Forensic Reports.
DMARC Record Syntax
DMARC is published as a DNS TXT record at _dmarc.example.com.
Complete Tag Reference
| Tag | Required | Description | Values | Default |
|---|---|---|---|---|
v | Yes | Version | DMARC1 | — |
p | Yes | Policy for domain | none, quarantine, reject | — |
sp | No | Policy for subdomains | none, quarantine, reject | Same as p |
rua | No* | Aggregate Report recipients | mailto:dmarc@example.com | None |
ruf | No | Forensic Report recipients | mailto:forensic@example.com | None |
adkim | No | DKIM Alignment mode | r (relaxed), s (strict) | r |
aspf | No | SPF Alignment mode | r (relaxed), s (strict) | r |
pct | No | Percentage of emails to apply policy to | 0-100 | 100 |
ri | No | Reporting interval (seconds) | e.g., 86400 | 86400 (24h) |
fo | No | Forensic Report options | 0, 1, d, s | 0 |
* rua is technically optional but strongly recommended — without it, you get no visibility.
Example Records
# Monitoring mode (start here)
v=DMARC1; p=none; rua=mailto:dmarc@example.com; ruf=mailto:forensic@example.com
# Quarantine mode (next step)
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com; adkim=r; aspf=r
# Full enforcement
v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s; pct=100
DMARC Alignment Explained
Alignment is DMARC's most important concept. It ensures that the domain authenticated by SPF or DKIM matches the domain in the visible "From:" header.
Relaxed vs. Strict Alignment
| Mode | SPF Alignment | DKIM Alignment |
|---|---|---|
Relaxed (default, adkim=r/aspf=r) |
Return-Path domain and From: domain must share the same Organizational Domain.bounce.example.com aligns with example.com ✅ |
DKIM d= domain and From: domain must share the same Organizational Domain.d=mail.example.com aligns with from@example.com ✅ |
Strict (adkim=s/aspf=s) |
Return-Path domain must exactly match the From: domain.bounce.example.com does NOT align with example.com ❌ |
DKIM d= domain must exactly match the From: domain.d=mail.example.com does NOT align with from@example.com ❌ |
Alignment Examples
# Email From: user@example.com
# SPF Relaxed Alignment
Return-Path: bounce@example.com → Aligned ✅ (same Organizational Domain)
Return-Path: bounce@mail.example.com → Aligned ✅ (same Organizational Domain)
Return-Path: bounce@other.com → NOT Aligned ❌
# DKIM Relaxed Alignment
DKIM d=example.com → Aligned ✅
DKIM d=mx.example.com → Aligned ✅ (same Organizational Domain)
DKIM d=google.com → NOT Aligned ❌
# For DMARC to PASS: At least ONE of SPF or DKIM must both PASS and be ALIGNED
DMARC Policies: The Path to Enforcement
The DMARC policy (p=) tells receiving servers what to do with emails that fail authentication. The recommended approach is a gradual rollout:
Phase 1: Monitor (p=none)
- No emails are blocked or quarantined
- Aggregate Reports are collected to understand your email ecosystem
- Use this phase to identify all legitimate senders and fix authentication issues
- Duration: 2-4 weeks minimum, often 2-3 months for complex organizations
Phase 2: Quarantine (p=quarantine)
- Failing emails are flagged as suspicious (typically moved to spam/junk)
- Start with
pct=10to apply the policy to only 10% of failing emails - Gradually increase: 10% → 25% → 50% → 75% → 100%
- Monitor reports at each stage for legitimate email being affected
Phase 3: Reject (p=reject)
- Failing emails are silently dropped — they never reach the recipient
- This is the strongest protection against Spoofing
- Again, start with a low
pctand gradually increase - Make sure ALL legitimate senders are properly authenticated before going to 100%
p=reject without proper preparation can cause legitimate emails to be silently dropped. Always follow the phased approach and monitor reports carefully.
Related articles
SPF (Sender Policy Framework)
Complete guide to SPF: record syntax, mechanisms, qualifiers, the 10-lookup limit, and common mistakes.
ReadDKIM (DomainKeys Identified Mail)
Understanding DKIM: how cryptographic signatures protect email integrity, key management, and selector strategies.
ReadUnderstanding DMARC Reports
How to read and interpret DMARC aggregate reports: XML structure, source IP analysis, and identifying threats.
Read