DMARC Policy: p=none vs p=quarantine vs p=reject
The p tag tells receiving mail servers what to do with mail that fails DMARC: none means monitor only, quarantine means treat it as suspicious (usually the spam folder), and reject means refuse it. Start at p=none, fix every legitimate sender using your reports, then move to quarantine and finally reject.
By Stephen Williams · Updated
What each DMARC policy does
| Policy | What receivers are asked to do | Use it when |
|---|---|---|
p=none | Nothing different: deliver as they normally would, and send you reports. | You're starting out or still identifying senders. |
p=quarantine | Treat failing mail as suspicious, typically by delivering it to the spam or junk folder. | Reports show your known senders pass and you want enforcement with a safety net. |
p=reject | Refuse failing mail during the SMTP conversation, so it is never delivered. | All legitimate mail passes DMARC and you've run quarantine without surprises. |
A DMARC policy is a request, not a command: each receiver combines it with its own filtering. For example, Microsoft 365 documents that when its "Honor DMARC record policy" setting is on, inbound mail failing a sender's p=quarantine goes to the Junk Email folder and mail failing p=reject is rejected.
Why p=none isn't protection
With p=none, a phishing message that forges your domain is handled exactly as it would be with no DMARC record at all. Its value is visibility: aggregate reports show every server sending mail as your domain and whether it passes SPF and DKIM with alignment. That's the information you need to enforce safely.
It is also the minimum Gmail, Yahoo and Outlook.com require from bulk senders, so many domains publish p=none and stop there. Treat it as step one, not the finish line. See the bulk sender requirements for the details.
A staged rollout plan
Stage 1: Inventory senders and authenticate them
List everything that sends mail as your domain: your mailbox provider, marketing and newsletter tools, transactional email services, CRM, help desk, billing and any servers or devices that send alerts. For each one, set up SPF and, more importantly, DKIM signing with your own domain so it can align. Check your work with the SPF checker and DKIM checker.
Stage 2: Publish p=none and collect reports
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comAggregate reports arrive as compressed XML attachments, usually once a day per receiver. Upload them to the DMARC report analyzer to see which sources pass and which fail.
Stage 3: Fix what fails
- A legitimate service that passes SPF or DKIM but fails DMARC is authenticating with its own domain. Turn on custom DKIM with your domain in that service, or set a custom return-path (MAIL FROM) on your domain.
- A service failing both SPF and DKIM needs to be added to SPF and configured for DKIM.
- Unknown sources that fail everything are usually spoofing or forwarding; that's what enforcement is for.
Stage 4: Move to p=quarantine
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.comSome guides suggest ramping with pct (for example 10, 25, 50, then 100). Be aware that DMARCbis (RFC 9989) removes pct because values other than 0 and 100 were rarely applied accurately, and replaces pct=0 with the testing flag t=y. Watch your reports for a couple of weeks at full quarantine before moving on.
Stage 5: Move to p=reject and keep monitoring
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.comKeep the rua address and keep reading reports. New tools get added, vendors change their sending infrastructure, and DKIM keys get rotated; the reports are how you notice before your mail is rejected.
Example timeline
Timing depends on how many services send as your domain. As an illustration, a small organization with a mailbox provider and a couple of SaaS senders might plan:
| When | Policy | Exit criteria before the next step |
|---|---|---|
| Weeks 0-1 | Set up SPF and DKIM for every sender | Every known sender signs with your domain. |
| Weeks 1-5 | p=none | A full month of reports with all legitimate sources passing. |
| Weeks 5-8 | p=quarantine | No legitimate sources failing; no user reports of missing mail. |
| Week 8 onward | p=reject | Ongoing: review reports regularly and after any new tool is added. |
What can break under enforcement
- Forgotten senders: the quarterly survey tool or the scanner that emails PDFs. Reports from the p=none stage are how you find them.
- Forwarding: SPF fails after forwarding, but an intact DKIM signature still passes, which is why DKIM matters more than SPF for DMARC.
- Mailing lists: lists that add footers or subject tags can break DKIM. Many receivers rely on ARC to recognize trusted intermediaries.
- Third parties sending from your main domain: consider giving marketing tools their own subdomain (such as news.example.com) so they can be authenticated and enforced separately.
Subdomains and parked domains
Subdomains without their own DMARC record inherit the parent's policy, or the sp policy if you set one. DMARCbis adds np for subdomains that don't exist in DNS at all. Once the main domain is at reject, a common final state is:
v=DMARC1; p=reject; sp=reject; np=reject; rua=mailto:dmarc-reports@example.comFor domains that never send email, skip the rollout and publish v=DMARC1; p=reject; with an SPF record of v=spf1 -all. The DMARC tag reference covers every tag in detail.
Sources
Frequently asked questions
Is p=none enough to meet the Google, Yahoo and Microsoft sender requirements?
Yes. Gmail, Yahoo and Outlook.com require bulk senders to publish a DMARC record and pass DMARC with an aligned From domain, and all three accept p=none as the minimum policy. It satisfies the requirement but doesn't protect your domain from spoofing.
Should I go straight from p=none to p=reject?
Only for simple domains where reports show every legitimate sender passing DMARC. For most organizations a quarantine stage is safer: if a forgotten sender starts failing, its mail lands in spam instead of bouncing, and the reports show you what to fix.
How long should I stay at p=none?
There's no fixed period. Stay until your aggregate reports show that every legitimate source of mail passes DMARC, and cover at least one full business cycle so monthly senders such as invoices and newsletters appear in the reports.
Does p=reject stop all phishing?
No. DMARC stops other people from sending mail that uses your exact domain in the From address. It doesn't stop lookalike domains, display-name spoofing or compromised mailboxes, so keep user training and inbound filtering in place.
What happens to forwarded email under p=reject?
Forwarding usually breaks SPF because the forwarder's server isn't in your SPF record, but an intact DKIM signature still passes, so DMARC passes. Mailing lists that modify messages can break DKIM too; many receivers use ARC to recognize such trusted intermediaries.