The tags
| Tag | Values | Meaning |
|---|---|---|
| v | DMARC1 | Version; must come first |
| p | none | quarantine | reject | What receivers do with failing mail — required |
| sp | none | quarantine | reject | The same for subdomains; p= when left out |
| pct | 0–100 | Share of failing mail the policy applies to; 100 when left out |
| rua | mailto:… | Where daily aggregate reports go |
| ruf | mailto:… | Where reports on single failing messages go; rarely sent |
| adkim, aspf | r | s | Relaxed or strict alignment for DKIM and SPF; relaxed when left out |
| fo | 0 | 1 | d | s | When failure reports are wanted |
Moving to reject without losing mail
- 1Monitor
Publish
p=nonewith a report address and leave it for two to four weeks. The aggregate reports list every server that sent mail as your domain — your own, your providers’, and anyone spoofing you. - 2Fix your own sources
Every legitimate source must pass SPF or DKIM for your domain: add missing includes to SPF, turn on DKIM signing with your domain at each service that sends for you.
- 3Quarantine, then reject
Move to
p=quarantine, if you like withpct=25first, and raise it while the reports stay clean. Then switch top=reject.
; step 1: monitoring
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
; step 3: enforcing, subdomains included
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"Reports to another domain
When rua points to an address at another domain — a report service, or your company’s main domain — that domain has to agree to receive them, or receivers do not send the reports. It does so with one record that names your domain:
example.com._report._dmarc.reports.example.net. TXT "v=DMARC1"Report services publish a wildcard record for this. The checker above asks for the record of every outside address in rua and says which ones are missing it.
Frequently asked
What does DMARC do?
It tells receiving mail servers what to do with a message whose visible From domain is not confirmed by SPF or DKIM — deliver it anyway (p=none), put it in spam (quarantine) or refuse it (reject) — and asks them to send you reports. A message passes DMARC when SPF or DKIM passes for a domain that matches the From domain.
p=none, quarantine or reject — which should I use?
Start with p=none and a rua= address, and read the reports for a few weeks: they show every server that sends mail as your domain. Once all of your own mail passes, move to quarantine — pct= lets you apply it to part of the failing mail first — and then to reject. p=none on its own protects nothing.
What are rua and ruf?
rua is where receivers send aggregate reports, usually once a day: which addresses sent mail as your domain, how much, and whether SPF and DKIM passed. ruf asks for failure reports on single messages, which few large providers send. Reports for another domain's address are only sent if that domain publishes an authorisation record, which this checker tests.
What is DMARC alignment?
The rule that the domain SPF or DKIM vouches for must match the From domain. Relaxed alignment, the default, accepts a subdomain (mail.example.com for example.com); strict alignment (adkim=s, aspf=s) requires the exact name. Mail services that sign with their own domain fail alignment until you set them up to sign as yours.
Why does my subdomain show the main domain's record?
A subdomain without a DMARC record of its own falls under the record of its organisational domain — the name you registered — with that record's sp= policy, or p= when there is no sp=.