⚠ Email authentication

What is DMARC?

DMARC ties SPF and DKIM together and tells receiving servers what to do with mail that fails. Here is how it works and how to publish your first record.

Guide · 3 min read · updated 2026-08-01

The problem DMARC solves

The visible From address on an email is trivial to forge — nothing in the base email protocol checks it. That is why phishing that appears to come from your domain lands in inboxes.

SPF and DKIM each authenticate part of a message, but on their own neither protects the address your recipients actually see. A spoofer can pass SPF for their own domain while forging your From. DMARC closes that gap.

How DMARC works

DMARC is a DNS TXT record published at _dmarc.yourdomain.com. When a receiver gets a message, it checks SPF and DKIM, then requires that a passing result aligns with the domain in the From address.

If neither SPF nor DKIM passes in alignment with your domain, the message fails DMARC and the receiver applies your published policy. DMARC also asks receivers to send you reports about who is sending mail as you.

The three policies

The p= tag sets the policy. p=none means monitor only — take no action, just report. p=quarantine tells receivers to treat failing mail with suspicion, usually the spam folder. p=reject tells them to block it outright.

Alignment can be relaxed (the default) or strict, controlled by the adkim and aspf tags. Relaxed alignment allows subdomains to match; strict requires an exact domain match.

Publishing your first record

Start in monitoring mode so you can see your mail streams before enforcing anything. Publish this TXT record at the name _dmarc:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

The rua address receives the daily aggregate reports. Leave it in monitoring for a few weeks, confirm your legitimate senders pass, then tighten the policy.

Reading the reports

Aggregate (rua) reports are XML summaries sent by receiving providers. They list the sending IPs using your domain and whether they passed SPF and DKIM — the inventory you need before moving to enforcement.

Once your real senders all pass, raise the policy to quarantine and finally reject. Our guide on fixing p=none walks through that rollout.

Check your own domain

Run a free live scan and see exactly where DMARC? stands for your domain.

DMARC Checker ▸

Frequently asked questions

What is the _dmarc record?

A DNS TXT record published at _dmarc.<yourdomain> that starts with v=DMARC1 and defines your DMARC policy and reporting addresses.

Does DMARC require SPF and DKIM?

Yes. DMARC passes when a message aligns with a passing SPF or DKIM check, so at least one must be correctly set up and aligned with your domain.

Is DMARC free?

Yes. It is just a DNS record. Some providers sell reporting dashboards, but publishing the record and receiving raw reports costs nothing.

How soon will I see DMARC reports?

Aggregate reports are typically sent once per day, so expect the first data within about 24 hours of publishing a record with a rua address.

// More guides
How to fix DMARC p=none
DMARC enforcement
How to set up an SPF record
SPF / sender authorization
How to enable DNSSEC
DNSSEC
HTTP security headers explained
Web security headers