Email Marketing

DMARC

Also called Domain-based Message Authentication, Reporting and Conformance

A published policy telling receiving servers what to do when authentication fails, plus reports on who sends as your domain.

Quick facts: DMARC

Category
Email Marketing
Also called
Domain-based Message Authentication, Reporting and Conformance
Level
Advanced
Affects
Spoofing protection, deliverability, bulk sender compliance
Where to see it
Your DNS panel, DMARC report analysers, sending platform authentication dashboards
In this article4
  1. How DMARC works
  2. Why DMARC matters
  3. Common mistakes with DMARC
  4. How to act on it

How DMARC works

Domain-based Message Authentication, Reporting and Conformance is a record you publish in DNS that does two jobs. It states what a receiving server should do with mail claiming to be from your domain that fails authentication, and it asks receivers to send you reports about the mail they see using your name.

The critical concept is alignment. SPF checks a hidden return-path domain and DKIM checks a signing domain, and neither has to match the from address a recipient actually reads. DMARC insists that at least one of them lines up with the visible domain. That is what turns two technical checks into real protection against someone displaying your business name.

Your policy can be set to three levels: monitor only, where nothing is blocked and you simply collect reports; quarantine, where failing mail is treated as suspicious and usually filed as spam; and reject, where failing mail is refused outright. Google and Yahoo now require bulk senders to publish a DMARC record, so for any business mailing at volume it has stopped being optional.

Why DMARC matters

It is the only one of the three records that protects the thing customers look at. Without it, a forger with their own valid authentication can put your business in the from line and pass every other check. With a reject policy in place, most of those messages never arrive — which matters for anyone whose customers send money, so remittance, banking, travel and education agencies feel it most.

The reports are just as useful. Aggregate reports show every source sending mail as your domain, including systems you had forgotten and services a colleague signed up for. It is the only complete inventory of your sending you will ever get.

Common mistakes with DMARC

Stopping at monitor is the big one. A record set to take no action satisfies a compliance checkbox and prevents nothing, yet it is where most domains sit years after setup because nobody scheduled the next step.

Jumping straight to reject is the opposite error and it is worse. Legitimate mail from a tool you overlooked will vanish without a bounce anyone chases, and invoices or booking confirmations are usually what disappear. Move up in stages and read the reports before each tightening.

The third is publishing the record with no address to receive reports, which throws away the most valuable part. The fourth is reading raw reports by hand — they arrive as machine-readable files, and without a tool to summarise them people give up after the first week.

How to act on it

Publish a monitoring policy with a reporting address first, and leave it long enough to see a full cycle of your sending — including monthly invoicing and any seasonal campaign. Use a reporting service or your platform’s own dashboard to read the results rather than opening the files yourself.

Work through the sources the reports reveal: authorise the legitimate ones properly through SPF and DKIM, and confirm the rest are forgeries or forwarding. When the legitimate sources are all passing and aligned, move the policy to quarantine, watch again, then to reject. Re-open the reports after any change of email host, marketing platform or website, because a new system sending as your domain will fail silently under a strict policy.

Do and do not

Do

  • Start on a monitoring policy with a working reporting address
  • Use a reporting tool instead of reading raw report files
  • Tighten to quarantine, then reject, once sources pass

Do not

  • Leave the policy on monitoring and call it protected
  • Jump straight to reject before auditing your senders
  • Ignore the reports after changing host or platform

Questions people ask about this

What does a DMARC policy of none actually do?

Nothing to the mail itself. It tells receiving servers to deliver failing messages as they normally would while still sending you reports. That makes it a sensible starting point, because you can see every source using your domain before anything gets blocked. It offers no protection against spoofing, so it should be a stage rather than a destination.

Will DMARC break my existing email?

Only if you move to a strict policy before authorising every legitimate sender. Failing mail under a reject policy is refused rather than delivered to spam, so an overlooked invoicing tool or booking system simply stops arriving. Start on monitoring, read the reports until the legitimate sources are all passing, then tighten in stages.

Do I need DMARC if I only send a few emails?

Protection from spoofing has little to do with how much you send. If your domain is worth impersonating — because you invoice clients, take bookings or handle money — a forger can use it whether you send daily or rarely. Bulk sender requirements aside, a published policy is worth having for any business domain.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.