Glossary / DMARC
DMARC: the rule for mail that fails checks
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving servers what to do with mail from your domain that fails SPF and DKIM: allow it, send it to spam, or reject it. It ties those checks to the visible From address and sends you reports. DMARC is what actually shuts down spoofing of your domain.
Check your site
DMARC is a TXT record at _dmarc.yourdomain with a p= policy. It passes only when SPF or DKIM not only succeed but are also aligned with the domain a person sees in the From line.
The policy has three levels: p=none just watches and collects reports, p=quarantine sends suspicious mail to spam, and p=reject refuses it outright. The rua= tag points to a mailbox where aggregate reports arrive, showing who sends mail in your name.
Without DMARC, SPF and DKIM alone do not protect the address the recipient sees, so a scammer can put your domain in the From line. DMARC ties everything together and makes forgery visible.
Example
_dmarc TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@techguard.space"
Common mistakes
- Setting p=reject before SPF and DKIM are solid, which blocks your own mail.
- Leaving p=none forever; it only monitors and gives no protection.
- Ignoring alignment: SPF or DKIM pass on a different domain than From, so DMARC still fails.
- Leaving out rua=, so you never see who is failing the checks.
Related terms
Found problems?
Slow hosting, SSL trouble or frequent downtime? Move to TomisHost: fast hosting with free SSL, daily backups and free migration help.
TomisHost hosting