Skip to content

DMARC

DMARC is a DNS record that tells receiving mail servers what to do with a message using your domain that failed SPF and DKIM, and where to send reports.

Filip Kostecki

Published

Without DMARC anyone can send a message with your address in the From field, and you will not find out. Nor will you learn that your own form or your emails to subscribers fail the check and end up in spam. DMARC builds on SPF and DKIM and adds a policy and reports.

How does it work?

  1. SPF is a DNS record listing the servers allowed to send email from your domain. SPF checks the technical address in the message envelope, not the From address shown in the mailbox, so it is not enough on its own.
  2. DKIM is a signature on the message, made with a key whose public part you publish in DNS. Every system that sends in your name signs its messages with a key for your domain.
  3. DMARC is a TXT record named _dmarc.example.com, for example v=DMARC1; p=none; rua=mailto:dmarc@example.com. A message passes when SPF or DKIM passes with a domain that matches the From address (RFC 9989, May 2026).
  4. The receiving server applies the policy from the record to messages that failed, and sends you aggregate reports, usually once a day.
  5. You read the reports, fix the senders that fail, and only then tighten the policy.
Policy What the receiver does with a message that failed
none nothing, it only collects data and sends reports
quarantine treats it as suspicious, usually sends it to spam
reject refuses it

Google requires SPF, DKIM and DMARC from senders of 5,000 messages a day or more to Gmail accounts (Google). A small business is usually below that line.

Example from practice

In a small business at least 2 systems usually send email from the domain: a mailbox, and a service that sends replies from the website form or emails to subscribers. Each needs its own SPF entry and its own DKIM signature. The policy moves from none to quarantine only when DMARC reports show that both paths pass. Our article on why contact form emails land in spam walks through the same setup from the form’s side. If your form sends through a provider’s API, DKIM has to be set up at that provider.

When does it make sense, and when not?

DMARC makes sense for every domain you send email from: staff mailboxes, the website form, emails to subscribers, the invoicing system. For a domain that sends nothing at all, Microsoft advises an SPF record of v=spf1 -all and a DMARC policy of reject, because there is no legitimate sending to break.

We set up email authentication together with DNS, forms and sending from your website as part of hosting and maintenance.

Check my email setup

What to watch out for

Errors in SPF

  • Two SPF records on one domain. The standard forbids it, and with two records the receiver treats SPF as an error. List all senders in one record.
  • More than 10 DNS lookups. Every include, a, mx, ptr, exists and redirect counts towards a limit of 10, and past it SPF is an error too. With many outside services the limit is easy to exceed.

No DKIM at an outside sender

When the sending system uses its own domain in the envelope address and does not sign with your domain’s key, SPF passes and DMARC fails. Set up DKIM for your domain at the sending provider.

Reject straight away

Tightening the policy without reports cuts off senders you forgot: the emails to your subscribers, the invoicing system, the shop. Start with none and tighten only when the reports show that all your sending passes.

Reports with no owner

Reports are XML files arriving daily from many servers. Send them to a separate address or a group, not to an employee’s mailbox, and name someone who reads them. Otherwise nobody sees the results.

Questions and answers

Does a small business need DMARC?

Yes. DMARC reports show who sends email in the name of your domain and whether your form and your emails to subscribers pass the check. The DMARC requirement applies to large senders, but Google requires everyone to have at least SPF or DKIM.

Which policy should I start with?

Start with none and send the reports to a separate address. None blocks nothing, it only collects data. When the reports show that all your sending passes, move to quarantine, and later to reject. Google advises waiting at least a week of clean reports before quarantine.

How can I check that SPF, DKIM and DMARC are set up correctly?

Send a test message to a tool such as learndmarc.com, which shows how a receiving server validates all three. A test with a real message matters because DKIM is only visible on an actual email.

See also

Articles that use this term

Filip Kostecki

Founder of FKDRIVE. Designs, builds and maintains web systems, automation and websites.

Let us talk about your project.

Thirty minutes online about one or two processes that eat the most time. If you would rather write, the contact form is just as good a route.

Book 30 minutes

COOKIES

Without cookies we are working in the dark

We have no way of telling which parts of this site help somebody and which ought to go. Consent switches on visit statistics, session recordings with form content masked automatically, and measurement of how our advertising performs. We do not trade in your data and we do not sell it to anyone.

You can change this at any time with the “Cookie settings” link in the footer. What exactly we collect →