What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with mail that claims to come from your domain but fails authentication. It also tells them where to send reports about what they saw.
Why it matters
Anyone can put your domain in the visible "From" address of a message. Without DMARC, a receiver has no instruction from you about what to do when that message is not really yours. Attackers use this for phishing, invoice fraud and brand impersonation. Enforcing DMARC lets you say "reject mail that is not authenticated as us."
Other benefits: you see every system that sends as you, including forgotten ones, and some mailbox providers give better treatment to authenticated mail.
The three building blocks
| Piece | What it does | Published as |
|---|---|---|
| SPF | Lists the servers allowed to send for a domain | TXT record on the domain |
| DKIM | Signs each message so the receiver can verify it was not altered and came from a key you control | TXT record at <selector>._domainkey.<domain> |
| DMARC | Ties SPF and DKIM to the visible From domain and sets the policy and reporting | TXT record at _dmarc.<domain> |
Alignment: the part people miss
A message passes DMARC when at least one of these is true:
- SPF passes and the domain SPF checked (the envelope sender) matches the From domain.
- DKIM passes and the domain in the DKIM signature (
d=) matches the From domain.
"Matches" depends on the alignment mode:
| Mode | Meaning | Example: From is mail.example.com |
|---|---|---|
| Relaxed (default) | Same organizational domain | example.com aligns |
| Strict | Exact same domain | Only mail.example.com aligns |
Tip: a message can pass SPF and DKIM on their own and still fail DMARC, because the passing domain is the sender's (for example a mail service provider) and not yours. Fixing this usually means configuring the service to sign with, or send from, your domain.
Reading a DMARC record
Example record for example.com:
v=DMARC1; p=none; rua=mailto:[email protected]; pct=100; adkim=r; aspf=r| Tag | Meaning | Values |
|---|---|---|
v |
Version, always first | DMARC1 |
p |
Policy for the domain | none, quarantine, reject |
sp |
Policy for subdomains; defaults to p if absent |
same as p |
pct |
Percentage of failing mail the policy applies to | 1 to 100, default 100 |
rua |
Where aggregate reports are sent | mailto: address |
ruf |
Where forensic (failure) reports are sent | mailto: address |
adkim / aspf |
Alignment mode for DKIM / SPF | r relaxed, s strict |
fo |
When to generate failure reports | 0, 1, d, s |
Note: the DMARC+ Managed DMARC tool generates the record for you and shows the report addresses that belong to your organization. See Managed record tools.
Policies
| Policy | What receivers are asked to do with failing mail | Use it when |
|---|---|---|
none |
Deliver as normal, but send reports | You are starting out and finding senders |
quarantine |
Treat as suspicious, typically the spam folder | Most legitimate senders pass and you want a safety net |
reject |
Refuse the message | All legitimate senders pass; you want to stop spoofing |
Receivers treat the policy as a request. Most honor it, but you should not rely on it as the only control.
Using pct to phase in
pct applies the policy to only part of the failing mail. For example p=quarantine; pct=25 asks receivers to quarantine a quarter of failing messages and treat the rest as none. It is a way to step up gradually. See From monitoring to enforcement.
Subdomains
Without sp, subdomains inherit p. If your main domain is enforced but you have unused subdomains, an attacker can still try them, so keep the inherited policy or set sp=reject once you know subdomain traffic is clean. If a subdomain has its own _dmarc record, that record wins for that subdomain.
Aggregate and forensic reports
| Report | Contents | Frequency |
|---|---|---|
Aggregate (rua) |
Counts by sending IP: volume, SPF result, DKIM result, what the receiver did | Usually daily, per receiver |
Forensic (ruf) |
Individual failing messages, sometimes with headers | Only some receivers send them |
Note: many large providers send aggregate reports but few send forensic reports. Forensic reports can contain personal data, so handle them with care. See Forensic reports.
Next steps
- Set up DMARC for the first time.
- Read From monitoring to enforcement.
- Learn to read the data in Reading DMARC reports.