What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email standard that protects the From address people see. A domain publishes a policy in DNS telling receivers what to do when a message using its name fails both SPF and DKIM: deliver it, send it to spam or reject it. Receivers can also send reports back.

Also called: Domain-based Message Authentication, Reporting and Conformance, DMARC record, DMARC policy

Updated October 2026. Sources are numbered and listed at the end.

On this page

How DMARC works

SPF and DKIM each prove something about a domain, but neither one has to be the domain shown in the From line. DMARC ties them to it.1

  1. The domain publishes a policy. It is a TXT record at _dmarc.example.com, for example v=DMARC1; p=reject; rua=mailto:reports@example.com.
  2. A message arrives and the receiver runs the SPF and DKIM checks as usual.
  3. The receiver checks alignment. DMARC passes only if SPF or DKIM passed for a domain that matches the one in the From address.
  4. If nothing aligns, the policy applies. The receiver looks at the p= value to see what the domain owner asked for.
  5. Reports go back. Receivers send the address in rua= a regular summary of who has been sending mail under the domain’s name.

The three DMARC policies

What each policy asks receivers to do with mail that fails DMARC.
PolicyWhat it asksWhen it’s used
p=noneNo preference. Handle the mail as usual and send reportsWhile a domain is finding out who sends for it
p=quarantineTreat failing mail as suspicious, usually by sending it to spamA middle step once the real senders pass
p=rejectRefuse failing mail outrightFull protection against forged use of the domain

Alignment can be relaxed or strict. Relaxed, the default, accepts a subdomain: mail signed by mail.example.com aligns with a From address at example.com. Strict demands an exact match. The record sets this with the aspf and adkim tags.

Why DMARC matters

The From address is the one part most people look at, and without DMARC nothing stops a stranger from typing your domain into it. A policy of reject tells every receiving server to turn that mail away. The reports matter too: they are often how a company first learns which services send mail in its name. Gmail requires DMARC from bulk senders, those sending around 5,000 or more messages a day.3

A standard that was just updated

DMARC was first written down in RFC 7489 in 2015, as an informational document.2 In May 2026 the IETF replaced it with RFC 9989, which puts DMARC on the standards track. Existing records keep working. The new version drops the old pct tag, which applied a policy to only a share of mail, and adds a simple testing flag in its place.1

Where you’ll see DMARC

In the headers of an email you receive, your provider writes the result on the Authentication-Results line, for example dmarc=pass. You can read any domain’s policy with dig +short TXT _dmarc.example.com. When judging a suspicious email, the DMARC result is the one to check first, because it is the one tied to the address you see.

DMARC in Secria

The DMARC policy for secria.me is reject, with strict alignment for both SPF and DKIM, so receivers are told to refuse mail that only pretends to come from a Secria address. When you connect your own domain on Mail Plus or Secria Pro, Secria shows you the DMARC record to add, along with the MX, SPF and DKIM records, and checks them for you.

Sources

  1. IETF, RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) (May 2026).
  2. IETF, RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) (March 2015). Replaced by RFC 9989.
  3. Google, Email sender guidelines (Google Workspace Admin Help).

Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.

Questions about DMARC

Do I need DMARC if I already have SPF and DKIM?

Yes, if you want to protect the address people see. SPF and DKIM can both pass for a domain that has nothing to do with the From line. DMARC is the check that requires them to match it.

What does p=none mean?

It means the domain owner states no preference for mail that fails DMARC. Receivers handle it as they normally would and still send reports. It is a starting point for watching who sends mail under your name, not protection.

What is the difference between quarantine and reject?

With quarantine, the domain asks receivers to treat failing mail as suspicious, which usually means the spam folder. With reject, it asks them to refuse the mail so it is never delivered.

What is a DMARC report?

It is a summary that receiving providers send to the address in a domain’s DMARC record. It lists which servers sent mail using the domain and whether that mail passed SPF, DKIM and DMARC. It doesn’t include the messages themselves.

What does a DMARC fail mean on an email I received?

It means neither SPF nor DKIM passed for the domain in the From address. The message may be forged, or the sender’s setup may be broken. If it asks you to pay, log in or open an attachment, don’t trust it.

Email that’s ready for what comes next.

Post-quantum encryption on every plan, free included.

Start free

Explore Secria Mail