Try free for 14 days

Basics

What is DMARC? A simple guide for SMEs

Any company with its own domain can fall victim to spoofed emails: fraudsters write to customers, suppliers or employees in your company’s name. DMARC is the standard that tells recipients how to handle such forgeries.

3 min readHow well is your domain protected? Check my domain for free

Key points at a glance

  • DMARC determines what happens to emails that forge your domain: nothing, the spam folder, or rejection.
  • Only the p=reject level truly protects your customers and suppliers from forged emails sent in your name.
  • The daily reports show who is sending in your name – provided someone actually reviews them.

DMARC in one sentence

DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) is a DNS record that specifies what a receiving mail server should do with emails that claim to come from your domain but fail the SPF and DKIM checks – and where it should send you reports about this.

How DMARC works

DMARC builds on two older mechanisms: SPF checks whether the sending server is allowed to send for your domain; DKIM checks a digital signature on the email. DMARC adds the decisive point: the verified domain must match the visible sender address (“alignment”). Only this makes the protection work where people actually look – at the sender shown in the mailbox.

  • An email passes DMARC if SPF or DKIM passes and the respective domain matches the sender address.
  • If it fails, the recipient applies your policy.
  • Every day, large mailbox providers send you aggregate reports (XML) about who has sent in your name.
How SPF, DKIM and DMARC work together
SPFIs this server allowed to send for the domain?
DKIMIs the digital signature genuine and the email unchanged?
DMARCDoes a passed check match the visible sender address?
PassedThe email is delivered normally.
FailedThe recipient applies your policy: none, quarantine or reject.
ReportYou find out who is sending in your name.

The three levels: none, quarantine, reject

The policy is set in the p= field of the record. A typical starting point looks like this: _dmarc.example.com TXT “v=DMARC1; p=none; rua=mailto:dmarc@example.com”.

  • p=none: monitor only. Nothing is blocked, but you receive reports.
  • p=quarantine: emails that fail land in the spam folder.
  • p=reject: emails that fail are rejected. Only this level truly protects your domain against forgeries.
The three levels compared
  1. p=noneMonitor only, nothing is blocked
  2. p=quarantineForgeries land in the spam folder
  3. p=rejectForgeries are rejected

No protectionFull protection

Why DMARC is essential for SMEs today

Since 2024, Google and Yahoo have required senders of larger volumes to have a DMARC record, and Microsoft has done the same for Outlook since 2025. Even those sending little benefit: DMARC reduces the risk of your emails landing in spam, and fraudsters can no longer misuse your domain unchecked.

Good to know

DMARC is a single DNS record with no licence costs. You start with p=none, and not a single email gets blocked.

Common pitfalls

  • The record is set to p=none and stays there for years – providing no real protection.
  • Nobody reads the reports because they arrive as XML files.
  • Services such as newsletter tools, CRM or accounting software send in the domain’s name without SPF or DKIM set up, and get blocked once p=reject is active.

p=none provides no protection

With p=none you only see forgeries in the reports – they are still delivered. Plan the path to p=reject from the start.

How DomainRadar helps

DomainRadar receives your DMARC reports and translates them into a clear overview: which services send in your name, which are set up correctly and where forgeries appear. A wizard guides you step by step from p=none to p=reject.

The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.

More guides

How does your domain measure up?

DomainRadar continuously checks the SPF, DKIM and DMARC of your domains and tells you in plain words what to do.