Email Marketing

DMARC

Also called Domain-based Message Authentication Reporting and Conformance, DMARC policy, DMARC record

A DNS record telling mail servers what to do with email that fails authentication for your domain, and asking them to report back to you.

Quick facts: DMARC

Category
Email Marketing
Also called
Domain-based Message Authentication Reporting and Conformance, DMARC policy, DMARC record
Level
Advanced
Affects
Protection against spoofing and invoice fraud, inbox placement, bulk sender compliance, BIMI eligibility
Where to see it
Your DNS host, DMARC report readers, Google Postmaster Tools, NCSC guidance on email security, Gmail "Show original"
In this article4
  1. How DMARC works
  2. Why it matters for a UK business
  3. Common mistakes
  4. How to act on it

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with an email claiming to come from your domain when it fails authentication, and asks them to send you reports on what they see. It turns SPF and DKIM from background checks into a policy you control.

How DMARC works

When an email arrives, the receiving server checks SPF and DKIM, then asks whether either one passed for a domain that aligns with the visible From address. If at least one did, the message passes DMARC. If neither did, the server applies the policy published in your DMARC record, a TXT record at _dmarc.yourdomain.co.uk:

  • p=none Deliver as normal, but report. This is monitoring only.
  • p=quarantine Treat failing mail as suspicious, usually by putting it in spam.
  • p=reject Refuse failing mail outright.

A simple record reads v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk. The rua address receives aggregate reports: XML files from providers such as Google and Microsoft listing which servers sent mail as your domain and whether it passed. An sp= tag can set a different policy for subdomains.

Alignment can be relaxed or strict. Relaxed, the default, accepts a subdomain: mail signed by news.yourdomain.co.uk aligns with a From address at yourdomain.co.uk. Strict, set with adkim=s or aspf=s, demands an exact match. Most small businesses should keep the default, because marketing platforms often send from a subdomain.

Why it matters for a UK business

Without DMARC at enforcement, anyone can send email that shows your domain in the From line. Fake invoices and requests to change bank details, sent in the name of a real supplier, are a familiar route into business email fraud, and the National Cyber Security Centre recommends that UK organisations use DMARC. Public sector bodies have been expected to use it under the government’s email security standard for years.

There is a marketing reason as well. Since 2024, Gmail and Yahoo have required bulk senders to publish a DMARC record, and authenticated, aligned mail builds the domain reputation behind your inbox placement. Reaching quarantine or reject is also a condition for showing your logo through BIMI.

Common mistakes

  • Publishing p=none and leaving it there for years. Monitoring alone protects nobody.
  • Jumping straight to p=reject before finding every legitimate sender, so invoices from the accounting software or alerts from the booking system start bouncing.
  • Sending reports to an inbox nobody reads, or one that fills up with XML files.
  • Publishing two DMARC records for the same domain, which makes both invalid.
  • Forgetting parked domains that never send email. They can be spoofed too, so give them p=reject and an SPF record that authorises no senders.

How to act on it

Publish a record at p=none with a rua address, ideally feeding a report reader so the XML becomes a readable list of senders. Over a few weeks, identify each legitimate service and fix its SPF and DKIM alignment with your own domain. When the reports show your real mail passing consistently, move to p=quarantine, then to p=reject.

After that, check the reports monthly and whenever you add a new tool that sends email. For the wider picture of how these records fit together, see email authentication. If you want help weighing this against the rest of your marketing priorities, my digital marketing strategy and consulting service is a good starting point.

Do and do not

Do

  • Start at p=none with a report address
  • Fix alignment for every legitimate sender
  • Move to quarantine, then reject

Do not

  • Stay at p=none indefinitely
  • Jump to reject before reading the reports
  • Leave parked domains unprotected

Questions people ask about this

Is p=none enough to meet Gmail and Yahoo's sender rules?

At the time of writing (October 2026), their bulk sender requirements ask for a valid DMARC record, and p=none meets that minimum. It does not stop anyone spoofing your domain, though, and BIMI needs quarantine or reject. Treat p=none as the start of a project with an end date.

How long does it take to move DMARC to p=reject?

For a small business with a handful of sending tools, a few weeks to a couple of months is common, mostly spent identifying senders in the reports and fixing their alignment. Organisations with many systems and suppliers take longer. The pace depends on how quickly each service's settings can be changed, not on DMARC itself.

What do DMARC aggregate reports show?

For each reporting provider and day, they list the IP addresses that sent mail using your domain, how many messages each sent, and whether SPF, DKIM and DMARC passed. They contain no message content. A report reader turns them into a summary, so you can spot both forgotten legitimate senders and impersonation attempts.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.