Authentication
DMARC: the rule that tells mailbox providers what to do with fakes
Three policies, one report address, and why spoofers tend to go quiet once you publish it.
DMARC is the policy layer on top of SPF and DKIM. It says: when a message claims to be from my domain and fails the checks, do this. It also asks for reports, so you can see who is sending in your name.
The three policies
- p=none: do nothing, just report. Start here to learn what is sending.
- p=quarantine: send failures to spam.
- p=reject: refuse them outright. The strongest setting.
What a record needs
- A TXT record at
_dmarc.yourdomainwith the policy and a report address (rua=). - Alignment: the domain in the From line must match the domain that passed SPF or DKIM.
- Reports arrive as XML, usually once a day. Read them, or use a free viewer.
The effect in practice
- Phishers who copy your domain often stop once a reject policy is live, because providers refuse their mail.
- Legitimate senders you forgot about show up in the reports. Fix them before moving to reject.