How DMARC works
Domain-based Message Authentication, Reporting and Conformance is a record you publish in DNS that does two jobs. It states what a receiving server should do with mail claiming to be from your domain that fails authentication, and it asks receivers to send you reports about the mail they see using your name.
The critical concept is alignment. SPF checks a hidden return-path domain and DKIM checks a signing domain, and neither has to match the from address a recipient actually reads. DMARC insists that at least one of them lines up with the visible domain. That is what turns two technical checks into real protection against someone displaying your business name.
Your policy can be set to three levels: monitor only, where nothing is blocked and you simply collect reports; quarantine, where failing mail is treated as suspicious and usually filed as spam; and reject, where failing mail is refused outright. Google and Yahoo now require bulk senders to publish a DMARC record, so for any business mailing at volume it has stopped being optional.
Why DMARC matters
It is the only one of the three records that protects the thing customers look at. Without it, a forger with their own valid authentication can put your business in the from line and pass every other check. With a reject policy in place, most of those messages never arrive — which matters for anyone whose customers send money, so remittance, banking, travel and education agencies feel it most.
The reports are just as useful. Aggregate reports show every source sending mail as your domain, including systems you had forgotten and services a colleague signed up for. It is the only complete inventory of your sending you will ever get.
Common mistakes with DMARC
Stopping at monitor is the big one. A record set to take no action satisfies a compliance checkbox and prevents nothing, yet it is where most domains sit years after setup because nobody scheduled the next step.
Jumping straight to reject is the opposite error and it is worse. Legitimate mail from a tool you overlooked will vanish without a bounce anyone chases, and invoices or booking confirmations are usually what disappear. Move up in stages and read the reports before each tightening.
The third is publishing the record with no address to receive reports, which throws away the most valuable part. The fourth is reading raw reports by hand — they arrive as machine-readable files, and without a tool to summarise them people give up after the first week.
How to act on it
Publish a monitoring policy with a reporting address first, and leave it long enough to see a full cycle of your sending — including monthly invoicing and any seasonal campaign. Use a reporting service or your platform’s own dashboard to read the results rather than opening the files yourself.
Work through the sources the reports reveal: authorise the legitimate ones properly through SPF and DKIM, and confirm the rest are forgeries or forwarding. When the legitimate sources are all passing and aligned, move the policy to quarantine, watch again, then to reject. Re-open the reports after any change of email host, marketing platform or website, because a new system sending as your domain will fail silently under a strict policy.