DMARC Rollout: Moving from p=none to p=reject Without Breaking Your Email
A step-by-step plan to go from monitoring to full DMARC enforcement safely, using aggregate reports to find every legitimate sender first.
A DMARC record with p=none is a good first step, but it does not protect your domain: spoofed messages are still delivered. The real value of DMARC comes with p=quarantine or p=reject. The risk is that enforcing too early blocks your own legitimate mail. The solution is a staged rollout driven by data.
Step 1: Publish a monitoring record
Start with a policy that changes nothing but sends you aggregate reports:
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"Step 2: Collect and read aggregate reports
Receivers such as Google, Yahoo and Microsoft send daily XML reports listing every IP that sent mail using your domain, and whether SPF and DKIM passed and aligned. Raw XML is hard to read, so use a DMARC report analyzer. Collect at least two to four weeks of data so that monthly jobs (invoices, newsletters) show up.
Step 3: Identify and fix every legitimate source
- List every service that sends as your domain: mail server, Google Workspace or Microsoft 365, CRM, marketing platform, help desk, billing system
- For each one, enable DKIM signing with your domain — DKIM survives forwarding better than SPF
- Where possible, configure a custom return-path (bounce) domain so SPF also aligns
- Unknown sources in the reports are either forgotten tools or spoofing — investigate before enforcing
Step 4: Move to quarantine gradually
When the reports show that all legitimate mail passes, switch to quarantine. You can use the pct tag to apply the policy to a portion of failing mail first:
"v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc-reports@example.com"
"v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com"Step 5: Enforce with reject
After a few weeks at full quarantine with no legitimate failures, move to reject. Keep the rua address — you still want to know when a new tool starts sending without authentication.
"v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"Don't forget subdomains and parked domains
- The
sptag sets the policy for subdomains; without it they inheritp - Domains that never send email should publish
v=DMARC1; p=rejectand an SPF record ofv=spf1 -allto prevent spoofing - Only one DMARC record may exist at
_dmarc— multiple records make DMARC fail entirely
Typical timeline
For a small organization with a handful of sending services, the whole process takes 4–8 weeks. Larger organizations with many departments and vendors often need several months. Rushing is what breaks email; patience is what makes enforcement painless.
Check your domain in seconds
Verify SPF, DKIM, DMARC and blacklist status and get a prioritized list of fixes.