Fix guides › DMARC: none to reject
Move DMARC from p=none to reject, safely
p=none only watches. Fake email using your domain is still delivered. This plan gets you to full protection in about two months without blocking your own messages.
Last reviewed 7 October 2026
Weeks 1–4: monitor and read the reports
Publish a monitoring record with a report address, if you haven’t already:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Inboxes such as Gmail and Microsoft will send daily XML reports listing every server that sent email using your domain, and whether it passed. A free DMARC report service turns these into a readable list. You’re looking for your own services that fail: an invoicing tool, a website contact form, a newsletter platform.
Fix each sender that fails
For each legitimate service that fails, set up SPF (add its include to your record) or, better, DKIM (most services let you add a signing key for your domain). Repeat until the reports show your real email passing.
Weeks 5–6: quarantine a small share
v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@yourdomain.com
A quarter of failing email now goes to spam. Watch the reports and your inbox for complaints. If something legitimate is caught, fix it before going further. Then raise pct to 50, then 100.
Weeks 7–8: reject
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com
Fake email using your domain is now refused outright. Keep the report address so you notice if a new tool starts sending email on your behalf without being set up.
Things to watch out for
- Forwarded email can fail SPF. DKIM survives forwarding, which is why setting up DKIM for every sender matters.
- Subdomains follow your main policy unless you add
sp=. Leave it out unless you have a reason. - New tools: whenever someone adds a service that sends email on your behalf, set up its SPF or DKIM before it goes live.
The DMARC record builder writes the record for each stage, and the DMARC checker confirms what’s live.