What is DMARC?

DMARC is an email authentication standard that stops criminals sending messages that appear to come from your domain. The name stands for Domain-based Message Authentication, Reporting and Conformance, and it works by building on two older checks, SPF and DKIM, to tell receiving mail servers what to do when a message fails authentication. For any business that sends email, DMARC is the difference between a spoofed phishing campaign landing in your customers’ inboxes and being rejected outright.
What is DMARC and why does it matter?
Without DMARC, anyone can put your domain in the from address of an email. Attackers exploit this to impersonate your brand, sending invoices, password resets and phishing links that look genuine. DMARC closes the gap by letting you publish a policy in your DNS that says, in effect, only mail that truly comes from us should be trusted, and here is what to do with anything that is not. It also protects your legitimate email, because a healthy DMARC record improves how mailbox providers judge your domain.
How DMARC works
DMARC sits on top of SPF and DKIM. SPF lists the servers allowed to send mail for your domain, and DKIM adds a cryptographic signature that proves a message was not altered. DMARC adds a crucial extra requirement called alignment: the domain that passes SPF or DKIM must match the domain shown to the recipient. A message only passes DMARC if it passes SPF or DKIM and that check aligns with the visible from address. This is what makes spoofing so much harder.
You publish DMARC as a single DNS TXT record on the special host _dmarc under your domain. Receiving servers read it on every incoming message and apply your instructions.
DMARC policies
- p=none only monitors and reports. It changes nothing about delivery and offers no protection on its own.
- p=quarantine tells receivers to treat failing mail as suspicious, usually sending it to spam.
- p=reject tells receivers to refuse failing mail outright. This is the goal, because it actually blocks spoofing.
Many domains get stuck on p=none and never gain real protection. Our guide on how to fix DMARC p=none explains how to move safely to enforcement.
DMARC reports
One of the most useful parts of DMARC is reporting. By adding a rua address to your record, you receive daily aggregate reports showing every source sending mail as your domain, how much passed authentication, and how much failed. These reports reveal both attackers impersonating you and legitimate services you forgot to authenticate, so you can fix alignment before tightening the policy.
Setting up DMARC the right way
The safe path is to publish SPF and DKIM first, then start DMARC at p=none purely to collect reports. Once the reports confirm all your genuine mail is authenticated and aligned, raise the policy to quarantine and then to reject. For a full walkthrough of all three records, see our post on setting up DMARC, SPF and DKIM, and the related explainers on SPF and DKIM.
How to check your DMARC record
A DMARC record can exist but still leave you exposed if it is stuck on p=none or points reports nowhere. Run a security scan with EzyAudit AI and you will see whether DMARC is published, what policy it enforces, and whether SPF and DKIM support it, all explained in plain language. See the full list of checks we perform. For the formal specification, DMARC is defined in IETF RFC 7489.
A DMARC record at p=reject is one of the strongest signals that your domain cannot be easily spoofed. Scan your website now to see where your email authentication stands today.