DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It uses SPF and DKIM authentication results to help receiving mail systems decide how messages using a domain should be handled.
Why is DMARC important?
Attackers may attempt to send fraudulent messages while displaying a company domain in the visible From address. DMARC gives receiving systems a published policy for evaluating these messages.
How does DMARC work with SPF and DKIM?
DMARC is not an independent authentication method. It builds on SPF and DKIM and evaluates whether authenticated domains align with the domain visible to the recipient.
DMARC policy levels
- p=none: Used primarily for monitoring.
- p=quarantine: Suggests treating failed messages as suspicious.
- p=reject: Suggests rejecting messages that fail DMARC.
Why are DMARC reports useful?
Reports can reveal which systems are sending email on behalf of your domain. They are useful for identifying unauthorized senders and legitimate services that have not been configured correctly.
Deploy DMARC gradually
Moving immediately to a strict policy can affect legitimate mail. Monitoring first and correcting SPF and DKIM alignment generally provides a safer path.
For the fundamentals, read What Are SPF, DKIM and DMARC?.