Telling servers what to do.
WHAT IT IS
A DNS record stating what receiving servers should do with mail that fails SPF and DKIM.
WHAT IT ADDS
SPF and DKIM check authorisation.
DMARC states the policy, and provides reporting.
THE POLICY OPTIONS
- None: take no action, but report
- Quarantine: treat failing mail as suspicious
- Reject: refuse failing mail entirely
HOW TO INTRODUCE IT
Start with none, and read the reports.
That shows you what is sending as your domain, including things you forgot.
Then move to quarantine, then reject.
WHY NOT START WITH REJECT
If a legitimate service is not properly authorised, its mail stops immediately.
The gradual approach finds those first.
WHAT THE REPORTS SHOW
Which servers sent mail claiming to be your domain Whether it passed authentication
WHAT PEOPLE DISCOVER
Services they forgot were sending Attempts to forge their domain
WHAT IT PROTECTS
Your domain from being used to send fraudulent mail in your name.
That matters commercially as well as technically.