Step-by-Step DMARC Implementation
Step 1: Audit Your Email Senders
Before touching DNS, make a list of every service and server that sends email using your domain:
- Your own mail server(s)
- Email service provider (Google Workspace, Microsoft 365, etc.)
- Marketing tools (Mailchimp, HubSpot, etc.)
- Transactional email (SendGrid, Amazon SES, Postmark, etc.)
- CRM/Support (Salesforce, Zendesk, Freshdesk, etc.)
- Billing/Invoicing systems
- Web application (password resets, notifications)
Step 2: Configure SPF
Create an SPF record that includes all authorized senders:
v=spf1 include:_spf.google.com include:sendgrid.net include:servers.mcsv.net ip4:198.51.100.10 ~all
Use ~all (Soft Fail) initially. Switch to -all (Hard Fail) after monitoring.
Step 3: Configure DKIM
Set up DKIM signing for each service. Each service will provide a DNS record to publish. Verify each signature is valid using a DKIM checker.
Step 4: Publish DMARC in Monitoring Mode
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:your-rua@dmarc.provider.tools; ruf=mailto:your-ruf@dmarc.provider.tools; fo=1"
Step 5: Monitor Reports for 2-4 Weeks
Use Provider.tools to analyze incoming Aggregate Reports. Look for:
- Legitimate senders that are failing authentication (fix their SPF/DKIM)
- Unknown senders (investigate — legitimate or Spoofing?)
- High fail rates from specific IPs
Step 6: Move to Quarantine (Gradual)
v=DMARC1; p=quarantine; pct=10; rua=mailto:rua@dmarc.provider.tools
Monitor for a week, then increase pct to 25%, 50%, 75%, 100%.
Step 7: Move to Reject
v=DMARC1; p=reject; rua=mailto:rua@dmarc.provider.tools; adkim=s; aspf=s
Same gradual pct increase. Congratulations — your domain is now fully protected!
Handling Third-Party Senders
Third-party email services are the #1 source of DMARC Alignment failures. Here's how to configure the most common ones:
Google Workspace
- SPF:
include:_spf.google.com - DKIM: Generate in Admin Console → Apps → Google Workspace → Gmail → Authenticate email
- Alignment: Automatic when DKIM is configured with your domain
Microsoft 365
- SPF:
include:spf.protection.outlook.com - DKIM: Enable in Microsoft 365 Defender → Email authentication → DKIM
- Alignment: Publish CNAME records for selector1 and selector2
Amazon SES
- SPF:
include:amazonses.comor use a custom MAIL FROM domain - DKIM: Enable Easy DKIM in SES → Verified identities → Your domain
- Custom MAIL FROM: Critical for SPF Alignment — set to
mail.yourdomain.com
SendGrid
- SPF:
include:sendgrid.net - DKIM: Domain Authentication in Settings → Sender Authentication
- Branded Links: Use a subdomain like
email.yourdomain.com
Mailchimp
- SPF:
include:servers.mcsv.net - DKIM: Authenticate domain in Account → Domains
marketing.example.com) with its own SPF, DKIM, and DMARC records.
Related articles
DMARC Deep Dive
Complete DMARC guide: policies, alignment modes, subdomain handling, and the path from monitoring to enforcement.
ReadUnderstanding DMARC Reports
How to read and interpret DMARC aggregate reports: XML structure, source IP analysis, and identifying threats.
ReadTroubleshooting Guide
Common DMARC, SPF, and DKIM problems and how to diagnose and fix them.
Read