LearnDMARC
DMARC

DMARC — Domain-based Message Authentication

How DMARC ties together SPF and DKIM to give domain owners control over email spoofing.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol defined in RFC 7489. It builds on SPF and DKIM by adding a policy layer — allowing domain owners to specify what should happen to emails that fail authentication — and a reporting mechanism so senders can see who is sending email on their behalf.

How DMARC Works

DMARC requires that either SPF or DKIM (or both) pass and "align" with the domain in the visible From header. Alignment means the authenticated domain matches the From domain.


• SPF alignment: the Return-Path domain matches the From domain.

• DKIM alignment: the d= domain in the DKIM signature matches the From domain.


If alignment fails, the receiving server follows the DMARC policy: none, quarantine, or reject.

DMARC Record Syntax

DMARC records are published as TXT records at _dmarc.{domain}.


Example:

_dmarc.example.com IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; ruf=mailto:forensics@example.com; pct=100"

Key tags:

• p= — policy: none | quarantine | reject

• rua= — aggregate report destination

• ruf= — forensic/failure report destination

• pct= — percentage of messages the policy applies to (0–100)

• sp= — subdomain policy (defaults to p= if not set)

• adkim= / aspf= — alignment mode (r=relaxed, s=strict)

DMARC Policies Explained

• p=none: Monitor only. No action is taken on failing mail. Use this during rollout to collect reports without affecting delivery.

• p=quarantine: Failing messages are sent to the spam/junk folder. A step up from none — reduces visibility of spoofed email.

• p=reject: Failing messages are outright rejected during SMTP. This is the strongest protection and the end goal for most domains.


Google, Yahoo, and other major providers now require p=quarantine or p=reject for bulk senders.

DMARC Reporting

DMARC generates two types of reports:


• Aggregate reports (RUA): Daily XML summaries from receiving mail servers showing authentication pass/fail counts by source IP. Invaluable for discovering unauthorized senders.

• Forensic reports (RUF): Individual copies of failing messages (not supported by all providers due to privacy concerns).


Use a DMARC report analyzer like MailGeeks.com to make sense of aggregate reports at scale.

DMARC Rollout Strategy

1. Deploy SPF and DKIM for all legitimate mail streams.

2. Publish p=none with rua= reporting to start collecting data.

3. Analyze aggregate reports for 2–4 weeks — identify all legitimate senders.

4. Fix any missing SPF/DKIM for legitimate sources.

5. Move to p=quarantine with pct=10 and gradually increase to 100.

6. Once confident, move to p=reject for full protection.