DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with an email claiming to come from your domain when it fails authentication, and asks them to send you reports on what they see. It turns SPF and DKIM from background checks into a policy you control.
How DMARC works
When an email arrives, the receiving server checks SPF and DKIM, then asks whether either one passed for a domain that aligns with the visible From address. If at least one did, the message passes DMARC. If neither did, the server applies the policy published in your DMARC record, a TXT record at _dmarc.yourdomain.co.uk:
- p=none Deliver as normal, but report. This is monitoring only.
- p=quarantine Treat failing mail as suspicious, usually by putting it in spam.
- p=reject Refuse failing mail outright.
A simple record reads v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk. The rua address receives aggregate reports: XML files from providers such as Google and Microsoft listing which servers sent mail as your domain and whether it passed. An sp= tag can set a different policy for subdomains.
Alignment can be relaxed or strict. Relaxed, the default, accepts a subdomain: mail signed by news.yourdomain.co.uk aligns with a From address at yourdomain.co.uk. Strict, set with adkim=s or aspf=s, demands an exact match. Most small businesses should keep the default, because marketing platforms often send from a subdomain.
Why it matters for a UK business
Without DMARC at enforcement, anyone can send email that shows your domain in the From line. Fake invoices and requests to change bank details, sent in the name of a real supplier, are a familiar route into business email fraud, and the National Cyber Security Centre recommends that UK organisations use DMARC. Public sector bodies have been expected to use it under the government’s email security standard for years.
There is a marketing reason as well. Since 2024, Gmail and Yahoo have required bulk senders to publish a DMARC record, and authenticated, aligned mail builds the domain reputation behind your inbox placement. Reaching quarantine or reject is also a condition for showing your logo through BIMI.
Common mistakes
- Publishing p=none and leaving it there for years. Monitoring alone protects nobody.
- Jumping straight to p=reject before finding every legitimate sender, so invoices from the accounting software or alerts from the booking system start bouncing.
- Sending reports to an inbox nobody reads, or one that fills up with XML files.
- Publishing two DMARC records for the same domain, which makes both invalid.
- Forgetting parked domains that never send email. They can be spoofed too, so give them p=reject and an SPF record that authorises no senders.
How to act on it
Publish a record at p=none with a rua address, ideally feeding a report reader so the XML becomes a readable list of senders. Over a few weeks, identify each legitimate service and fix its SPF and DKIM alignment with your own domain. When the reports show your real mail passing consistently, move to p=quarantine, then to p=reject.
After that, check the reports monthly and whenever you add a new tool that sends email. For the wider picture of how these records fit together, see email authentication. If you want help weighing this against the rest of your marketing priorities, my digital marketing strategy and consulting service is a good starting point.
