DMARC Policy Explained (none, quarantine, reject)

DMARC tells receiving mail servers what to do when SPF and/or DKIM fail. It also enables reporting so you can see who sends email using your domain.

DMARC Policies

Policy Effect
p=none Monitor only (no enforcement)
p=quarantine Mark failed messages as spam/junk
p=reject Reject failed messages (strongest protection)

Recommended Setup Path

  1. Start with monitoring: p=none
  2. Review reports for legitimate sources
  3. Move to p=quarantine
  4. Finally enforce with p=reject

Starter DMARC Record

v=DMARC1; p=none; rua=mailto:reports@yourdomain.com