Key points at a glance
- p=reject is the goal: only then are forged emails sent in your name rejected.
- The path runs through observing, fixing and gradually tightening the policy – usually over several weeks.
- Reviewing the reports at every stage catches problems before genuine emails get rejected.
Step 1: observe with p=none
Set up a DMARC record with p=none and a reporting address (rua). Nothing is blocked, but you find out who sends in your name. Plan for at least two to four weeks so that infrequent senders, such as monthly invoices, also become visible.
- p=noneObserve for two to four weeks
- Fix sendersSPF and DKIM for every service
- p=quarantineFirst part of the emails, then all
- p=rejectForgeries are rejected
StartFull protection
Step 2: identify and fix all senders
Go through the reports and assign each source: your own mail server, newsletter tool, CRM, ticketing system, accounting software. Set up SPF and DKIM with your domain for every legitimate service. Unknown sources are often forgeries – or forgotten services.
Step 3: quarantine step by step
Once almost all legitimate emails pass DMARC, switch to p=quarantine, at first only for part of the emails (pct=25), then for all of them. After each stage, check the reports for at least a week.
Don’t rush it
Jumping straight from p=none to p=reject risks rejecting genuine invoices or newsletters. Every level needs clean reports.
Step 4: p=reject
If the reports stay clean, switch to p=reject. Forged emails are now rejected. Remember subdomains (sp=) and domains that send no email at all: these too should have p=reject, together with an SPF record of “v=spf1 -all”.
Step 5: stay on top of it
New services, a change of mail provider or an expired DKIM key can disrupt a clean setup again at any time. So keep evaluating the reports continuously even after the switch.
Every time you add a new service
When you introduce a new tool that sends emails in your name, set up SPF and DKIM for it before it goes live.
How DomainRadar helps
DomainRadar’s p=reject wizard only suggests the next level once enough data is available: at least 14 days on p=none or 7 days on one level, reports from multiple recipients, and a high pass rate with hardly any unknown sources. This way you always know whether the next step is safe.
The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.