DMARC Explained: Policies, Alignment and Reporting

What DMARC checks, what p=none, quarantine and reject each ask receivers to do, and why you read the reports before you tighten the policy.

DMARC is a DNS policy for what a receiver should do when a message using your domain in the From address is not authenticated in alignment with SPF or DKIM. It also requests aggregate reports so you can see who is sending as you.

Definition you can quote: DMARC is a published policy that ties the visible From domain to a passing, aligned SPF or DKIM result, and states what to do when that tie fails.

The three policies

p=none asks receivers to deliver as they otherwise would, and to send you reports. It is how you discover a payroll tool, a support desk, or a salesperson's plug-in that sends as your domain and is not yet aligned. p=quarantine asks receivers to treat failures with suspicion, often the spam folder. p=reject asks them not to deliver failures.

Moving from none to reject because a blog said to, without reading a report, will break the sender you forgot. Read the reports, align each legitimate sender, then tighten.

Where outreach fits

Cold email from a domain with no DMARC, or with a policy your sending service does not satisfy, fails before the sentence matters. Sendblox should use a domain you have already aligned. The product drafts and can hold the send for a person. It does not invent a DMARC policy, and this page is not a substitute for the DMARC.org specification or your DNS host's own instructions.

Before you publish a change for DMARC, write down the date, the record you edited, and the one message you used as a test. A week later, check whether that test still matches production. Provider rules, DNS includes, and CRM fields all move. A page that was true in general can be wrong on your domain if nobody looked again. Keep the send small until that check is dull. One contact, one objective, a person reading the draft. If the test fails, stop the campaign. Do not widen it to see whether a larger list forgives a broken setup.

Before you publish a change for DMARC, write down the date, the record you edited, and the one message you used as a test. A week later, check whether that test still matches production. Provider rules, DNS includes, and CRM fields all move. A page that was true in general can be wrong on your domain if nobody looked again. Keep the send small until that check is dull. One contact, one objective, a person reading the draft. If the test fails, stop the campaign. Do not widen it to see whether a larger list forgives a broken setup.