Why you need DMARC
SPF and DKIM verify the server and the signature, but they don't tell the receiver what to do when the check fails. DMARC closes this gap: the domain owner publishes a policy, and mail providers enforce it and send reports on all mail sent on the domain's behalf. Since 2024 Gmail and Yahoo require DMARC from everyone who sends bulk mail.
How to roll it out gradually
- p=none with an rua address — collect reports for a few weeks and identify every service that sends mail on your behalf. The DMARC report analyzer will help you make sense of the reports.
- Add all legitimate services to SPF and set up DKIM for them.
- p=quarantine, first with pct=25, then 100 — forged messages go to spam.
- p=reject — full protection: messages that fail the check are rejected.
Alignment
DMARC requires the domain in the “From” address to match the domain verified by SPF or DKIM. Relaxed alignment allows subdomains (news.example.com for example.com), strict alignment only an exact match. Relaxed is enough for most domains.