Try free for 14 days

Practice

The path to p=reject: step by step

Only with p=reject is your domain truly protected against forgery. Many companies, however, stay at p=none for fear of blocking their own emails. With an orderly approach, the switch succeeds safely.

3 min readHow well is your domain protected? Check my domain for free

Key points at a glance

  • p=reject is the goal: only then are forged emails sent in your name rejected.
  • The path runs through observing, fixing and gradually tightening the policy – usually over several weeks.
  • Reviewing the reports at every stage catches problems before genuine emails get rejected.

Step 1: observe with p=none

Set up a DMARC record with p=none and a reporting address (rua). Nothing is blocked, but you find out who sends in your name. Plan for at least two to four weeks so that infrequent senders, such as monthly invoices, also become visible.

The path at a glance
  1. p=noneObserve for two to four weeks
  2. Fix sendersSPF and DKIM for every service
  3. p=quarantineFirst part of the emails, then all
  4. p=rejectForgeries are rejected

StartFull protection

Step 2: identify and fix all senders

Go through the reports and assign each source: your own mail server, newsletter tool, CRM, ticketing system, accounting software. Set up SPF and DKIM with your domain for every legitimate service. Unknown sources are often forgeries – or forgotten services.

Step 3: quarantine step by step

Once almost all legitimate emails pass DMARC, switch to p=quarantine, at first only for part of the emails (pct=25), then for all of them. After each stage, check the reports for at least a week.

Don’t rush it

Jumping straight from p=none to p=reject risks rejecting genuine invoices or newsletters. Every level needs clean reports.

Step 4: p=reject

If the reports stay clean, switch to p=reject. Forged emails are now rejected. Remember subdomains (sp=) and domains that send no email at all: these too should have p=reject, together with an SPF record of “v=spf1 -all”.

Step 5: stay on top of it

New services, a change of mail provider or an expired DKIM key can disrupt a clean setup again at any time. So keep evaluating the reports continuously even after the switch.

Every time you add a new service

When you introduce a new tool that sends emails in your name, set up SPF and DKIM for it before it goes live.

How DomainRadar helps

DomainRadar’s p=reject wizard only suggests the next level once enough data is available: at least 14 days on p=none or 7 days on one level, reports from multiple recipients, and a high pass rate with hardly any unknown sources. This way you always know whether the next step is safe.

The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.

More guides

How does your domain measure up?

DomainRadar continuously checks the SPF, DKIM and DMARC of your domains and tells you in plain words what to do.