Dmarc Overview

Set up DMARC for the first time

This guide takes one domain from "nothing published" to "reports arriving". It ends at monitoring mode. Enforcement is covered in From monitoring to enforcement.

Before you start

  • Access to edit DNS for the domain.
  • The DMARC module enabled for your account.
  • A list of the systems you know send mail as this domain (corporate mailbox, marketing tool, support desk, billing system).
  • The DKIM selector of your main mail system, if you use DKIM.

Step 1: Add the domain

  1. Open DMARC+ > Domains.
  2. Select the add option to open the Add Domain pane.
  3. Fill in the fields.
Field What to enter
Domain name The domain, for example example.com (no http://, no www)
Domain criticality High, Medium or Low. Used to prioritize and filter.
DKIM Selector Required. The selector of your main mail system.
Parked Domain Turn on if the domain never sends mail. See Parked domains.
  1. Save. DMARC+ checks your DNS at once and stores what it finds for SPF, DKIM and DMARC.

Note: you can also organize domains into a domain group. Groups become filters in the Dashboard.

Step 2: Read the initial status

The domain card shows the state of each record and the DMARC policy it found.

Status Meaning
Valid Record found and well-formed
Invalid Record found but has an error
Not published Nothing found at the expected DNS name
Unknown The check could not complete

The policy shows as Reject, Quarantine, None, or a dash when there is no record.

Step 3: Get your reporting address

Your DMARC record must send reports to an address that DMARC+ reads. The address is unique to your organization and domain.

  1. Open DMARC+ > Tools > DMARC and pick the domain, or open Manage > Managed DMARC.
  2. Find the report addresses shown by the tool (aggregate and forensic).

Tip: the DMARC tool shows a warning when your published record has no rua or ruf address, or when it does not send to DMARC+.

Step 4: Publish a monitoring record

Choose one of two ways.

Option A: publish the record yourself

  1. Open Tools > DMARC > DMARC Generator or Manage > Managed DMARC and set the policy to None.
  2. Keep pct at 100 and alignment at Relaxed.
  3. Copy the generated record.
  4. In your DNS host, create a TXT record at _dmarc.<your domain> with that value.

Option B: use a managed record

A managed record lets you change the policy later from DMARC+ without editing DNS again. See Managed record tools. In short:

  1. Delete any existing TXT record at _dmarc.<your domain>. A CNAME cannot coexist with a TXT record.
  2. Generate the managed record in DMARC+ and publish the CNAME it gives you.

Note: publishing a monitoring record does not affect mail delivery.

Step 5: Verify SPF and DKIM

  1. Open Tools > SPF. Make sure the domain has exactly one SPF record and fewer than 10 lookups.
  2. Open Tools > DKIM, enter the selector and check that the key is found.
  3. If either is missing, use Managed record tools or your provider's guide: Microsoft 365, Google Workspace, third-party senders.

Step 6: Wait for reports

Receivers send aggregate reports about once a day. Expect the first data one to two days after publishing, and complete data after about two weeks.

After What to check
Day 1 to 2 The domain card shows volume; the Dashboard has points
Week 1 Aggregate Reports lists reporting receivers and sending IPs
Week 2 Every regular sender is identified

Checks before moving on

  • The DMARC record is visible under Tools > DMARC with a report address that goes to DMARC+.
  • The Dashboard shows data for the domain.
  • Known senders appear in Aggregate Reports.

If data does not appear, see Troubleshooting.

Next steps

  1. Read the Dashboard.
  2. Identify senders in the Aggregate Reports Explorer.
  3. Move to enforcement.