KorantixKorantix

Understand what your scan results mean / DMARC

DMARC in plain terms: policy, alignment, and reports

DMARC ties SPF and DKIM together and tells receivers what to do when a message fails both β€” and, if you ask it to, sends you a daily report of who's sending mail as your domain.

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS TXT record published at _dmarc.yourdomain.com. It does three things: declares a policy (what to do with mail that fails authentication), requires that SPF or DKIM β€œalign” with the visible From address, and optionally requests aggregate reports.

The policy tag (p=) has three values: β€œnone” just monitors and reports without affecting delivery, β€œquarantine” asks receivers to send failing mail to spam, and β€œreject” asks them to block it outright. Most domains that have DMARC at all are stuck on β€œnone” indefinitely β€” which means it's reporting on abuse of your domain but doing nothing to stop it.

Alignment is the part people miss: DMARC doesn't just check that SPF or DKIM passed β€” it checks that the domain that passed SPF/DKIM actually matches the domain in the visible β€œFrom:” header the recipient sees. A message can pass SPF for a totally different domain and still fail DMARC if that domain doesn't align with what's shown to the reader.

What to do: if you're on p=none, start collecting aggregate reports (rua=) and actually read them for a few weeks β€” you'll usually find legitimate senders (a CRM, a support tool, an old mail server) you forgot were sending as your domain. Fix or authorize those first, then move to quarantine, then reject.

Check this on your domain β†’