The stages

  1. p=none with rua — at least two, better four weeks. The goal is a complete list of every system sending in your name. Only when four weeks pass without anything unknown appearing at meaningful volume is the inventory finished.
  2. p=quarantine — two weeks. Failing messages land in the spam folder rather than nowhere. This is the stage where mistakes are still repairable, because the recipient can find the mail.
  3. p=reject — the steady state. Failing messages are refused in the SMTP dialogue; the sender gets a non-delivery report, the recipient sees nothing.
_dmarc.yourdomain.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; sp=quarantine; adkim=r; aspf=r"

What has to be settled before each stage

  • Every legitimate sender passes in alignment. “SPF pass” is not enough; what counts is pass in the reports' policy_evaluated column. A provider signing with their own domain passes SPF and still fails DMARC.
  • Both proofs in place where possible. With SPF alone you lose every forward. DKIM survives them — that combination is the actual reason tightening works without outages.
  • Subdomains are accounted for. sp= sets the policy for subdomains. Without it they inherit p= — including the ones nobody remembers are still sending.

What to do about pct

pct= applies the policy to only a share of messages and looks like a gentle dial. In practice it is less useful than it sounds: receivers round differently, some ignore the value, and at small volumes the sample is meaningless. Moving to the next stage for all messages, with a short observation window, is usually the more honest route. The ongoing revision of the DMARC standard plans to remove pct.

How you notice it was too early

After each tightening, stay alert for two days — that is how long the reports need to show the new state. Warning signs:

  • policy_evaluated suddenly reads disposition: quarantine for an IP belonging to a known internal system.
  • Colleagues report that replies to newsletters or ticket mail stop arriving.
  • A mailing list the domain posts to reports delivery problems — lists routinely break DKIM by editing the subject or appending a footer.

The way back is cheap: revert the policy, wait out the TTL, fix the cause, tighten again. Which is why lowering the _dmarc record's TTL to 300 seconds before a change pays off.

What becomes possible afterwards

An enforced policy is the prerequisite for BIMI — the logo in the inbox requires quarantine or reject. And it is the point at which abuse of your domain actually stops instead of merely being observed.

Verify your work

Once the DNS change is live, send an email to hello@analyzemy.email and check in the report whether it took effect.

Analyze your email now

Last updated: · All guides