DMARC
DMARC Record Setup Guide
What alignment means, why a passing SPF check can still fail DMARC, and the staged path from none to reject.
Generador de registros DMARCPruébelo en su propio dominio primero. Gratis, sin cuenta.What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties SPF and DKIM together. It tells receiving servers what to do with mail that fails authentication (monitor with none, quarantine, or reject) and where to send reports.
Choosing a policy
Start at p=none to collect reports without affecting delivery, review who is sending as your domain, then tighten to p=quarantine and finally p=reject once legitimate mail passes. This staged rollout protects you from accidentally blocking real email.
Where the record lives
Publish the generated record as a TXT record at _dmarc.yourdomain.com. Add a rua address to receive aggregate reports so you can see exactly which sources pass and fail authentication.
What alignment actually means
DMARC does not just ask whether SPF or DKIM passed. It asks whether the domain that passed matches the From domain your reader sees. A message can pass SPF for a vendor domain and still fail DMARC, because the two domains do not align. That mismatch is the most common reason a correct-looking setup fails.
Moving from none to reject without breaking mail
Sit at p=none long enough to see a full billing cycle of reports, so quarterly and annual senders show up. Fix every legitimate source that fails alignment. Then move to quarantine with pct=25, watch, raise the percentage, and only then go to reject. Skipping the report-reading step is how legitimate mail gets blocked.
Check yours now
Build the record with the free DMARC record generator and confirm what resolves with the free email health check.
How to publish a DMARC record
Publish a DMARC policy, collect reports and tighten enforcement safely.
- Publish SPF and DKIM firstDMARC is a verdict on SPF and DKIM alignment. Without at least one of them passing and aligned, a strict DMARC policy will block your own mail.
- Generate a p=none recordSet the policy to none and add a rua address so aggregate reports start arriving. Nothing about delivery changes at this stage.
- Publish it at _dmarcCreate a TXT record at _dmarc.yourdomain.com with the generated value.
- Read the reportsWait at least two weeks and review which sources are sending as your domain and which fail alignment. Fix the legitimate ones.
- Tighten the policyMove to p=quarantine, then to p=reject once every legitimate source passes. Raise enforcement gradually with the pct tag if you send at volume.
Preguntas frecuentes
Do I need DMARC?
Yes if you send bulk mail to Gmail or Yahoo (at least p=none). For any domain, DMARC prevents spoofing and improves deliverability.
What policy should I start with?
Start with p=none to monitor, then move to quarantine and reject as you confirm your legitimate senders all pass SPF or DKIM alignment.
What is a rua address?
rua is the email address that receives DMARC aggregate reports, the XML summaries of who is sending mail using your domain and whether it passed authentication.
Does DMARC require SPF and DKIM?
DMARC builds on them: a message passes DMARC when it passes SPF or DKIM AND that authenticated domain aligns with the From domain. You need at least one aligned and passing.
How long should I stay at p=none?
Long enough to see every sender that uses your domain, which usually means at least one full billing cycle so quarterly and annual mail appears. Two weeks is a floor, not a target.
What is the difference between rua and ruf?
rua receives aggregate reports: daily XML summaries of pass and fail counts per source. ruf receives forensic reports: redacted copies of individual failing messages. Aggregate reports are what you act on; forensic reports help you diagnose a specific failure.
Más guías
- SPFSPF Record Setup Guide
- DKIMDKIM Record Setup Guide
- email headersReading Email Headers
- SPF flatteningSPF Flattening: When It Helps and When It Bites
Estas herramientas responden la pregunta una vez. El monitoreo continuo vuelve a revisar su dominio cada 6 horas y le avisa cuando la respuesta cambie, desde $14/mes. Precios
