What Is DMARC?
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that builds on SPF and DKIM. It allows domain owners to specify how receivers should handle emails that fail authentication checks, and provides reporting to monitor email traffic.
How It Works
DMARC is published as a DNS TXT record at _dmarc.yourdomain.com. It tells receiving servers to check if incoming emails pass SPF or DKIM and if the "From" domain aligns with the authenticated domain. Based on the DMARC policy (none, quarantine, reject), the receiver takes action on failures.
Why It Matters
DMARC is the only email authentication protocol that gives domain owners control over what happens to unauthorized emails. Without DMARC, even with SPF and DKIM in place, spoofed emails may still be delivered. DMARC also provides aggregate reports showing who is sending email on behalf of your domain.
Common Issues
- DMARC policy set to "none" providing no enforcement
- SPF and DKIM alignment failures
- Legitimate third-party senders not passing DMARC
- No reporting address configured
- Moving from p=none to p=reject too quickly

