Dmarc Overview

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with mail that claims to come from your domain but fails authentication. It also tells them where to send reports about what they saw.

Why it matters

Anyone can put your domain in the visible "From" address of a message. Without DMARC, a receiver has no instruction from you about what to do when that message is not really yours. Attackers use this for phishing, invoice fraud and brand impersonation. Enforcing DMARC lets you say "reject mail that is not authenticated as us."

Other benefits: you see every system that sends as you, including forgotten ones, and some mailbox providers give better treatment to authenticated mail.

The three building blocks

Piece What it does Published as
SPF Lists the servers allowed to send for a domain TXT record on the domain
DKIM Signs each message so the receiver can verify it was not altered and came from a key you control TXT record at <selector>._domainkey.<domain>
DMARC Ties SPF and DKIM to the visible From domain and sets the policy and reporting TXT record at _dmarc.<domain>

Alignment: the part people miss

A message passes DMARC when at least one of these is true:

  • SPF passes and the domain SPF checked (the envelope sender) matches the From domain.
  • DKIM passes and the domain in the DKIM signature (d=) matches the From domain.

"Matches" depends on the alignment mode:

Mode Meaning Example: From is mail.example.com
Relaxed (default) Same organizational domain example.com aligns
Strict Exact same domain Only mail.example.com aligns

Tip: a message can pass SPF and DKIM on their own and still fail DMARC, because the passing domain is the sender's (for example a mail service provider) and not yours. Fixing this usually means configuring the service to sign with, or send from, your domain.

Reading a DMARC record

Example record for example.com:

v=DMARC1; p=none; rua=mailto:[email protected]; pct=100; adkim=r; aspf=r
Tag Meaning Values
v Version, always first DMARC1
p Policy for the domain none, quarantine, reject
sp Policy for subdomains; defaults to p if absent same as p
pct Percentage of failing mail the policy applies to 1 to 100, default 100
rua Where aggregate reports are sent mailto: address
ruf Where forensic (failure) reports are sent mailto: address
adkim / aspf Alignment mode for DKIM / SPF r relaxed, s strict
fo When to generate failure reports 0, 1, d, s

Note: the DMARC+ Managed DMARC tool generates the record for you and shows the report addresses that belong to your organization. See Managed record tools.

Policies

Policy What receivers are asked to do with failing mail Use it when
none Deliver as normal, but send reports You are starting out and finding senders
quarantine Treat as suspicious, typically the spam folder Most legitimate senders pass and you want a safety net
reject Refuse the message All legitimate senders pass; you want to stop spoofing

Receivers treat the policy as a request. Most honor it, but you should not rely on it as the only control.

Using pct to phase in

pct applies the policy to only part of the failing mail. For example p=quarantine; pct=25 asks receivers to quarantine a quarter of failing messages and treat the rest as none. It is a way to step up gradually. See From monitoring to enforcement.

Subdomains

Without sp, subdomains inherit p. If your main domain is enforced but you have unused subdomains, an attacker can still try them, so keep the inherited policy or set sp=reject once you know subdomain traffic is clean. If a subdomain has its own _dmarc record, that record wins for that subdomain.

Aggregate and forensic reports

Report Contents Frequency
Aggregate (rua) Counts by sending IP: volume, SPF result, DKIM result, what the receiver did Usually daily, per receiver
Forensic (ruf) Individual failing messages, sometimes with headers Only some receivers send them

Note: many large providers send aggregate reports but few send forensic reports. Forensic reports can contain personal data, so handle them with care. See Forensic reports.

Next steps

  1. Set up DMARC for the first time.
  2. Read From monitoring to enforcement.
  3. Learn to read the data in Reading DMARC reports.