Key points at a glance
- DMARC determines what happens to emails that forge your domain: nothing, the spam folder, or rejection.
- Only the p=reject level truly protects your customers and suppliers from forged emails sent in your name.
- The daily reports show who is sending in your name – provided someone actually reviews them.
DMARC in one sentence
DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489) is a DNS record that specifies what a receiving mail server should do with emails that claim to come from your domain but fail the SPF and DKIM checks – and where it should send you reports about this.
How DMARC works
DMARC builds on two older mechanisms: SPF checks whether the sending server is allowed to send for your domain; DKIM checks a digital signature on the email. DMARC adds the decisive point: the verified domain must match the visible sender address (“alignment”). Only this makes the protection work where people actually look – at the sender shown in the mailbox.
- An email passes DMARC if SPF or DKIM passes and the respective domain matches the sender address.
- If it fails, the recipient applies your policy.
- Every day, large mailbox providers send you aggregate reports (XML) about who has sent in your name.
The three levels: none, quarantine, reject
The policy is set in the p= field of the record. A typical starting point looks like this: _dmarc.example.com TXT “v=DMARC1; p=none; rua=mailto:dmarc@example.com”.
- p=none: monitor only. Nothing is blocked, but you receive reports.
- p=quarantine: emails that fail land in the spam folder.
- p=reject: emails that fail are rejected. Only this level truly protects your domain against forgeries.
- p=noneMonitor only, nothing is blocked
- p=quarantineForgeries land in the spam folder
- p=rejectForgeries are rejected
No protectionFull protection
Why DMARC is essential for SMEs today
Since 2024, Google and Yahoo have required senders of larger volumes to have a DMARC record, and Microsoft has done the same for Outlook since 2025. Even those sending little benefit: DMARC reduces the risk of your emails landing in spam, and fraudsters can no longer misuse your domain unchecked.
Good to know
DMARC is a single DNS record with no licence costs. You start with p=none, and not a single email gets blocked.
Common pitfalls
- The record is set to p=none and stays there for years – providing no real protection.
- Nobody reads the reports because they arrive as XML files.
- Services such as newsletter tools, CRM or accounting software send in the domain’s name without SPF or DKIM set up, and get blocked once p=reject is active.
p=none provides no protection
With p=none you only see forgeries in the reports – they are still delivered. Plan the path to p=reject from the start.
How DomainRadar helps
DomainRadar receives your DMARC reports and translates them into a clear overview: which services send in your name, which are set up correctly and where forgeries appear. A wizard guides you step by step from p=none to p=reject.
The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.