All articles
DMARCAuthentication

DMARC Rollout: Moving from p=none to p=reject Without Breaking Your Email

A step-by-step plan to go from monitoring to full DMARC enforcement safely, using aggregate reports to find every legitimate sender first.

August 6, 20268 min read

A DMARC record with p=none is a good first step, but it does not protect your domain: spoofed messages are still delivered. The real value of DMARC comes with p=quarantine or p=reject. The risk is that enforcing too early blocks your own legitimate mail. The solution is a staged rollout driven by data.

Step 1: Publish a monitoring record

Start with a policy that changes nothing but sends you aggregate reports:

_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Step 2: Collect and read aggregate reports

Receivers such as Google, Yahoo and Microsoft send daily XML reports listing every IP that sent mail using your domain, and whether SPF and DKIM passed and aligned. Raw XML is hard to read, so use a DMARC report analyzer. Collect at least two to four weeks of data so that monthly jobs (invoices, newsletters) show up.

Step 3: Identify and fix every legitimate source

  • List every service that sends as your domain: mail server, Google Workspace or Microsoft 365, CRM, marketing platform, help desk, billing system
  • For each one, enable DKIM signing with your domain — DKIM survives forwarding better than SPF
  • Where possible, configure a custom return-path (bounce) domain so SPF also aligns
  • Unknown sources in the reports are either forgotten tools or spoofing — investigate before enforcing

Step 4: Move to quarantine gradually

When the reports show that all legitimate mail passes, switch to quarantine. You can use the pct tag to apply the policy to a portion of failing mail first:

"v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.com"
"v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com"

Step 5: Enforce with reject

After a few weeks at full quarantine with no legitimate failures, move to reject. Keep the rua address — you still want to know when a new tool starts sending without authentication.

"v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"

Don't forget subdomains and parked domains

  • The sp tag sets the policy for subdomains; without it they inherit p
  • Domains that never send email should publish v=DMARC1; p=reject and an SPF record of v=spf1 -all to prevent spoofing
  • Only one DMARC record may exist at _dmarc — multiple records make DMARC fail entirely

Typical timeline

For a small organization with a handful of sending services, the whole process takes 4–8 weeks. Larger organizations with many departments and vendors often need several months. Rushing is what breaks email; patience is what makes enforcement painless.

Check your domain in seconds

Verify SPF, DKIM, DMARC and blacklist status and get a prioritized list of fixes.