What Is DMARC? The Policy That Ties It Together
DICTIONARY · EMAIL

What Is DMARC?

DMARC is a policy framework that tells receiving servers what to do when SPF and DKIM checks fail.

In plain English

It adds two things: alignment, which requires the authenticated domain to match the visible sender, and a policy telling receivers whether to do nothing, quarantine, or reject failing mail.

It also provides reports, which reveal every service sending as your domain. Most organisations find one or two they had forgotten about.

What to know

Policy options
None for monitoring, quarantine, or reject.
Requires alignment
Authenticated domain must match the visible sender.
Provides reports
Showing everything sending as your domain.
Deploy gradually
Start at none, review reports, then tighten.

Why it matters

DMARC is what turns SPF and DKIM into actual protection. Without it, a failing check has no consequence, and anyone can spoof your domain.

Common mistakes

×Publishing reject before reviewing reports, blocking legitimate mail.
×Leaving the policy at none permanently.
×Ignoring the reports entirely.
×Forgetting a legitimate sending service and rejecting its mail.

FAQs

Which policy should I use?

Start at none, read the reports for a few weeks, then move to quarantine and reject.

Is DMARC required?

Effectively yes for bulk senders to major providers.

WRITTEN BY TARIQ SALLAM
Marketing Consultant. Entrepreneur. Content Creator.

I'm a marketing consultant, entrepreneur and content creator. I help businesses grow through practical marketing, websites, SEO, content and AI.

More About Tariq →