Understand what your scan results mean / DMARC
DMARC in plain terms: policy, alignment, and reports
DMARC ties SPF and DKIM together and tells receivers what to do when a message fails both β and, if you ask it to, sends you a daily report of who's sending mail as your domain.
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS TXT record published at _dmarc.yourdomain.com. It does three things: declares a policy (what to do with mail that fails authentication), requires that SPF or DKIM βalignβ with the visible From address, and optionally requests aggregate reports.
The policy tag (p=) has three values: βnoneβ just monitors and reports without affecting delivery, βquarantineβ asks receivers to send failing mail to spam, and βrejectβ asks them to block it outright. Most domains that have DMARC at all are stuck on βnoneβ indefinitely β which means it's reporting on abuse of your domain but doing nothing to stop it.
Alignment is the part people miss: DMARC doesn't just check that SPF or DKIM passed β it checks that the domain that passed SPF/DKIM actually matches the domain in the visible βFrom:β header the recipient sees. A message can pass SPF for a totally different domain and still fail DMARC if that domain doesn't align with what's shown to the reader.
What to do: if you're on p=none, start collecting aggregate reports (rua=) and actually read them for a few weeks β you'll usually find legitimate senders (a CRM, a support tool, an old mail server) you forgot were sending as your domain. Fix or authorize those first, then move to quarantine, then reject.