DMARC Policy
DMARC (Domain-based Message Authentication, Reporting and Conformance) policies build on SPF and DKIM authentication to specify how recipients should treat unauthenticated emails — and provides reporting on authentication failures.
Why This Matters
DMARC mechanics: domain owner publishes DNS record specifying policy (none = monitor only; quarantine = mark as spam; reject = block entirely) for unauthenticated messages, plus reporting addresses for authentication reports. DMARC reports identify: senders attempting to send as your domain (legitimate forgotten infrastructure or malicious spoofing attempts), authentication failures requiring investigation, and overall email program authentication health. DMARC adoption increasingly required — Gmail and Yahoo recently mandated DMARC for bulk senders. DMARC implementation typical phases: monitor (none policy), partial enforcement (quarantine), full enforcement (reject).
Frequently Asked Questions
Frequently Asked Questions
What DMARC policy should B2B senders use?
Start with 'p=none' to monitor authentication patterns; advance to 'p=quarantine' once authentication coverage confirmed; eventually 'p=reject' for full protection. Direct jump to enforcement risks blocking legitimate messages from misconfigured infrastructure.
Why are Gmail and Yahoo requiring DMARC?
Email security improvement and spoofing reduction. February 2024 Gmail/Yahoo requirements: bulk senders (5000+/day) must implement DMARC. Required for inbox placement at major consumer email providers.