DMARC record
What is a DMARC record?
A DMARC record is a line in your domain’s DNS telling receiving mail servers what to do with a message sent in your name that fails the SPF and DKIM checks. The policy is one of three: p=none only watches, p=quarantine sends the message to spam, p=reject refuses it. The reports that come back show every source mailing as your domain, your own systems and other people’s alike.
Example
A shop has three systems sending mail from its domain: the host sends order confirmations, the newsletter platform sends campaigns, the accounting software sends invoices. Some confirmations land in spam, and customers report an “unpaid invoice” message the company never sent. The fix has three parts:
- SPF. One line in DNS listing the servers allowed to send mail for the domain.
- DKIM. Each system signs its messages with a key, and the receiver checks the signature.
- DMARC. A record at
_dmarcunder your domain, saying what to do with a message that fails both checks, and where the reports should go:v=DMARC1; p=none; rua=mailto:[email protected].
For the first two or three weeks the record stays at p=none and only collects reports. Those reports show that the accounting software is missing from SPF and signs nothing, which explains part of the spam. Once every legitimate sender is in order, the policy moves to quarantine and then to reject. Only at that point does a forged message in your name stop reaching its recipient.
Why it matters for a business
Two things at once: delivery and your name. Google and Yahoo have required SPF, DKIM and DMARC from bulk senders (roughly 5,000 messages a day) since February 2024, and Microsoft applied comparable rules to Outlook.com in 2025, so without them confirmations and password resets drop into spam for part of your list. The other half is fraud: with no policy in place, anyone can write to your customers and your accountant from your domain, which is exactly how the “our bank details have changed” email begins. Email marketing rests on the same three records.
How to improve it
- List everything that sends mail from the domain: site, shop, newsletter, accounting, helpdesk, CRM.
- Publish DMARC at p=none with a reporting address, and read the reports instead of collecting them.
- Add the missing senders to SPF and turn on DKIM signing everywhere.
- Move to quarantine, then to reject, in steps if that feels safer.
- Watch the SPF limit of ten DNS lookups; with many tools it overflows and the check stops passing.
- Update the records whenever a tool changes, because an abandoned line is an open door.
These three records are part of the review we run under cybersecurity: a domain is as much a part of the defence as the server is.