What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication protocol that protects your domain from email spoofing, phishing attacks, and unauthorized use.
By Stephen Williams · Updated
Key points
- Where it lives: A TXT record at _dmarc.yourdomain.com. Publishing one doesn't change how you send mail.
- What it does: Tells receivers whether to deliver, quarantine or reject mail that fails SPF and DKIM checks for your domain, and where to send reports.
- Why now: Gmail, Yahoo and Outlook.com require one from bulk senders, roughly anyone sending 5,000 or more messages a day to their users.
How DMARC Works
Email Authentication Check
When an email is received, the receiving server checks if it passes SPF and DKIM authentication.DMARC Policy Lookup
The server looks up your domain's DMARC policy to determine what action to take.Action Taken
Based on your policy, the email is delivered, quarantined, or rejected.Reporting
Receivers send daily aggregate reports to the address in your rua tag, listing the servers that sent mail as your domain and whether each one passed.
DMARC Policy Options
- None (Monitor)
- Monitor and report, but don't block emails
- Quarantine
- Send suspicious emails to spam folder
- Reject
- Block suspicious emails completely
DMARC History Timeline
2003
SPF Concept Introduction
Meng Weng Wong proposed Sender Policy Framework, a way for a domain to list the servers allowed to send its mail.2004
DomainKeys Development
Yahoo developed DomainKeys, the predecessor to DKIM, which signs each message with a key published in DNS.2006
SPF Published
SPF was published as RFC 4408, an Experimental RFC. It became a Proposed Standard with RFC 7208 in 2014.2011
DKIM Published
DKIM was published as RFC 6376, the version receivers still verify today.2012
DMARC Announced
Google, Microsoft, Yahoo, PayPal and other mail providers and senders published the first DMARC specification at dmarc.org.2015
DMARC Specification
DMARC was published as RFC 7489, an Informational RFC that most receivers still follow.2016
Mailbox Providers Enforce
Google moved gmail.com's own DMARC policy to p=reject, following Yahoo and AOL, which published p=reject for their consumer domains in 2014.2017
Government Mandates
The U.S. Department of Homeland Security's Binding Operational Directive 18-01 required federal civilian agencies to deploy DMARC and reach p=reject.2021
Brand Logos in Gmail
Gmail made BIMI generally available, showing verified brand logos for domains that enforce DMARC.2024
Bulk Sender Requirements
Gmail and Yahoo began requiring SPF, DKIM and DMARC from bulk senders in February 2024, and Outlook.com followed in May 2025. See the bulk sender requirements.2026
DMARCbis Published
The IETF published the updated DMARC specification as RFC 9989 in May 2026, obsoleting RFC 7489. Existing records keep working; see what changed.
DMARC Technical Components
SPF (Sender Policy Framework)
SPF allows domain owners to specify which mail servers are authorized to send emails on behalf of their domain. It's published as a DNS TXT record and helps prevent email spoofing by verifying the sender's IP address.
v=spf1 include:_spf.google.com ~allDKIM (DomainKeys Identified Mail)
DKIM adds a digital signature to email headers, allowing receiving servers to verify that the email content hasn't been tampered with and that it truly comes from the claimed domain.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com...DMARC Record
The DMARC record ties SPF and DKIM together, specifying what action to take when emails fail authentication and where to send reports about email authentication results.
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.comEvery tag, with copy-paste examples, is explained in the DMARC tag reference.
Why Your Organization Needs DMARC
Without DMARC, anyone can put your domain in the From address and receivers have no instructions from you about what to do with it. SPF and DKIM don't close that gap on their own: SPF checks the hidden envelope sender rather than the address people see, and an unsigned message isn't a DKIM failure.
A DMARC record changes three things. Receivers check that SPF or DKIM passed for the same domain shown in the From address, they apply your policy to mail that doesn't, and they send you reports. Those reports are often the first complete list an organization sees of every service sending mail in its name, including the ones nobody remembered.
It's also expected now. Gmail and Yahoo (since February 2024) and Outlook.com (since May 2025) require a DMARC record from bulk senders, as covered in the bulk sender requirements, and BIMI logos only show for domains at p=quarantine or p=reject.
DMARC Implementation Steps
Set up SPF and DKIM
Make sure every service that sends as your domain passes SPF or DKIM. DMARC needs at least one of them to pass for your domain.Start with Monitor Policy
Publish p=none with a report address. Delivery doesn't change while you collect data.Analyze Reports
Read a few weeks of aggregate reports to find every service sending as your domain, then fix the ones that fail.Gradually Enforce
Move to p=quarantine, then p=reject, once your reports show only legitimate mail passing. The DMARC policy rollout guide covers each stage.
DMARCbis: The 2026 Update (RFC 9989)
In May 2026 the IETF published DMARCbis as RFC 9989, a Standards Track specification that replaces RFC 7489. Aggregate and failure reporting are now defined in companion documents, RFC 9990 and RFC 9991. Records still start with v=DMARC1, so nothing breaks, but a few tags changed:
pct,rfandriare removed.t=ymarks a policy as being tested (the equivalent of the old pct=0): receivers step it down one level, handling reject like quarantine and quarantine like none.npsets a policy for subdomains that don't exist, andpsdflags public suffix domains.- Receivers find the organizational domain with a DNS tree walk instead of the Public Suffix List.
What to do: drop rf and ri next time you edit your record, stop relying on pct values between 1 and 99, and add np=reject once your domain is at enforcement. The DMARC tag reference has the details.
DMARC FAQ
What are the three DMARC policies?
p=none asks receivers to handle failing mail as usual and just send you reports. p=quarantine asks them to treat failing mail as suspicious, which usually means the spam or junk folder. p=reject asks them to refuse failing mail outright. Most domains start at none and move to quarantine and then reject as their reports come back clean.
What is DMARC alignment?
DMARC passes only when SPF or DKIM passes for a domain that matches the domain in the visible From address. With relaxed alignment, the default, the organizational domains must match, so mail.example.com aligns with example.com. With strict alignment (adkim=s or aspf=s) the domains must match exactly.
What does the rua tag do?
rua tells receivers where to send aggregate reports: usually daily XML summaries listing the IP addresses that sent mail using your domain and whether each passed SPF, DKIM and DMARC. Use a dedicated mailbox or reporting service. If the address is on a different domain, that domain must publish an authorization record at yourdomain._report._dmarc.
What does pct do, and is it still supported?
In RFC 7489, pct applies the policy to a percentage of failing mail (default 100). DMARCbis (RFC 9989, May 2026) removes pct because values other than 0 and 100 were rarely applied accurately, and adds t=y to mark a policy as being tested. While receivers transition, use t=y together with pct=0 when testing.
Does a DMARC record cover subdomains?
Yes. A subdomain without its own DMARC record inherits the organizational domain's policy, or the sp= policy if you set one. DMARCbis adds np= for subdomains that don't exist in DNS. A subdomain can publish its own _dmarc record to override the parent.
Do I need both SPF and DKIM for DMARC?
DMARC passes if either aligned SPF or aligned DKIM passes, but you should set up both. DKIM survives forwarding, which usually breaks SPF, and Gmail, Yahoo and Outlook.com require both SPF and DKIM from bulk senders.
Create or Check Your DMARC Record
Build a record with a live preview, or check the one you already have. SPF and DKIM are checked alongside it, free and without signing up.