The stages
p=nonewithrua— at least two, better four weeks. The goal is a complete list of every system sending in your name. Only when four weeks pass without anything unknown appearing at meaningful volume is the inventory finished.p=quarantine— two weeks. Failing messages land in the spam folder rather than nowhere. This is the stage where mistakes are still repairable, because the recipient can find the mail.p=reject— the steady state. Failing messages are refused in the SMTP dialogue; the sender gets a non-delivery report, the recipient sees nothing.
What has to be settled before each stage
- Every legitimate sender passes in alignment. “SPF pass” is not enough; what counts is
passin the reports'policy_evaluatedcolumn. A provider signing with their own domain passes SPF and still fails DMARC. - Both proofs in place where possible. With SPF alone you lose every forward. DKIM survives them — that combination is the actual reason tightening works without outages.
- Subdomains are accounted for.
sp=sets the policy for subdomains. Without it they inheritp=— including the ones nobody remembers are still sending.
What to do about pct
pct= applies the policy to only a share of messages and looks like a gentle dial. In practice it is less useful than it sounds: receivers round differently, some ignore the value, and at small volumes the sample is meaningless. Moving to the next stage for all messages, with a short observation window, is usually the more honest route. The ongoing revision of the DMARC standard plans to remove pct.
How you notice it was too early
After each tightening, stay alert for two days — that is how long the reports need to show the new state. Warning signs:
policy_evaluatedsuddenly readsdisposition: quarantinefor an IP belonging to a known internal system.- Colleagues report that replies to newsletters or ticket mail stop arriving.
- A mailing list the domain posts to reports delivery problems — lists routinely break DKIM by editing the subject or appending a footer.
The way back is cheap: revert the policy, wait out the TTL, fix the cause, tighten again. Which is why lowering the _dmarc record's TTL to 300 seconds before a change pays off.
What becomes possible afterwards
An enforced policy is the prerequisite for BIMI — the logo in the inbox requires quarantine or reject. And it is the point at which abuse of your domain actually stops instead of merely being observed.