How DMARC works
SPF and DKIM each prove something about a domain, but neither one has to be the domain shown in the From line. DMARC ties them to it.1
- The domain publishes a policy. It is a TXT record at
_dmarc.example.com, for examplev=DMARC1; p=reject; rua=mailto:reports@example.com. - A message arrives and the receiver runs the SPF and DKIM checks as usual.
- The receiver checks alignment. DMARC passes only if SPF or DKIM passed for a domain that matches the one in the From address.
- If nothing aligns, the policy applies. The receiver looks at the p= value to see what the domain owner asked for.
- Reports go back. Receivers send the address in rua= a regular summary of who has been sending mail under the domain’s name.
The three DMARC policies
| Policy | What it asks | When it’s used |
|---|---|---|
| p=none | No preference. Handle the mail as usual and send reports | While a domain is finding out who sends for it |
| p=quarantine | Treat failing mail as suspicious, usually by sending it to spam | A middle step once the real senders pass |
| p=reject | Refuse failing mail outright | Full protection against forged use of the domain |
Alignment can be relaxed or strict. Relaxed, the default, accepts a subdomain: mail signed by mail.example.com aligns with a From address at example.com. Strict demands an exact match. The record sets this with the aspf and adkim tags.
Why DMARC matters
The From address is the one part most people look at, and without DMARC nothing stops a stranger from typing your domain into it. A policy of reject tells every receiving server to turn that mail away. The reports matter too: they are often how a company first learns which services send mail in its name. Gmail requires DMARC from bulk senders, those sending around 5,000 or more messages a day.3
A standard that was just updated
DMARC was first written down in RFC 7489 in 2015, as an informational document.2 In May 2026 the IETF replaced it with RFC 9989, which puts DMARC on the standards track. Existing records keep working. The new version drops the old pct tag, which applied a policy to only a share of mail, and adds a simple testing flag in its place.1
Where you’ll see DMARC
In the headers of an email you receive, your provider writes the result on the Authentication-Results line, for example dmarc=pass. You can read any domain’s policy with dig +short TXT _dmarc.example.com. When judging a suspicious email, the DMARC result is the one to check first, because it is the one tied to the address you see.
DMARC in Secria
The DMARC policy for secria.me is reject, with strict alignment for both SPF and DKIM, so receivers are told to refuse mail that only pretends to come from a Secria address. When you connect your own domain on Mail Plus or Secria Pro, Secria shows you the DMARC record to add, along with the MX, SPF and DKIM records, and checks them for you.
Related terms
Sources
- IETF, RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) (May 2026).
- IETF, RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) (March 2015). Replaced by RFC 9989.
- Google, Email sender guidelines (Google Workspace Admin Help).
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about DMARC
Do I need DMARC if I already have SPF and DKIM?
Yes, if you want to protect the address people see. SPF and DKIM can both pass for a domain that has nothing to do with the From line. DMARC is the check that requires them to match it.
What does p=none mean?
It means the domain owner states no preference for mail that fails DMARC. Receivers handle it as they normally would and still send reports. It is a starting point for watching who sends mail under your name, not protection.
What is the difference between quarantine and reject?
With quarantine, the domain asks receivers to treat failing mail as suspicious, which usually means the spam folder. With reject, it asks them to refuse the mail so it is never delivered.
What is a DMARC report?
It is a summary that receiving providers send to the address in a domain’s DMARC record. It lists which servers sent mail using the domain and whether that mail passed SPF, DKIM and DMARC. It doesn’t include the messages themselves.
What does a DMARC fail mean on an email I received?
It means neither SPF nor DKIM passed for the domain in the From address. The message may be forged, or the sender’s setup may be broken. If it asks you to pay, log in or open an attachment, don’t trust it.