DMARC Policy

DMARC (Domain-based Message Authentication, Reporting and Conformance) policies build on SPF and DKIM authentication to specify how recipients should treat unauthenticated emails — and provides reporting on authentication failures.

Why This Matters

DMARC mechanics: domain owner publishes DNS record specifying policy (none = monitor only; quarantine = mark as spam; reject = block entirely) for unauthenticated messages, plus reporting addresses for authentication reports. DMARC reports identify: senders attempting to send as your domain (legitimate forgotten infrastructure or malicious spoofing attempts), authentication failures requiring investigation, and overall email program authentication health. DMARC adoption increasingly required — Gmail and Yahoo recently mandated DMARC for bulk senders. DMARC implementation typical phases: monitor (none policy), partial enforcement (quarantine), full enforcement (reject).

Frequently Asked Questions

Frequently Asked Questions

What DMARC policy should B2B senders use?

Start with 'p=none' to monitor authentication patterns; advance to 'p=quarantine' once authentication coverage confirmed; eventually 'p=reject' for full protection. Direct jump to enforcement risks blocking legitimate messages from misconfigured infrastructure.

Why are Gmail and Yahoo requiring DMARC?

Email security improvement and spoofing reduction. February 2024 Gmail/Yahoo requirements: bulk senders (5000+/day) must implement DMARC. Required for inbox placement at major consumer email providers.

Related Terms