XiaTools

What Is a DMARC Record and How to Set It Up

Updated 30 Sept 2026

A DMARC record is a TXT entry in your domain's DNS that tells receiving mail servers how to handle emails failing authentication. By combining SPF and DKIM, it stops domain spoofing and protects your brand reputation. Setting up DMARC ensures your legitimate emails reach the inbox while blocking fraudulent messages sent in your name.

Understanding Email Authentication Frameworks

Before diving into DMARC, you must understand the two foundational pillars it relies upon: SPF and DKIM. Without these two checks functioning correctly, DMARC cannot protect your domain effectively.

The Role of SPF

Sender Policy Framework (SPF) is a DNS record that lists all the authorized IP addresses and servers allowed to send email on behalf of your domain. When a receiving mail server gets an email from support@example.com, it looks up the SPF record for example.com. If the sending server's IP address matches an entry in that list, the SPF check passes.

However, SPF has notable limitations. It breaks when emails are forwarded, and it only checks the "Return-Path" address, which is often hidden from the end user who only sees the "From" header.

The Role of DKIM

DomainKeys Identified Mail (DKIM) adds a cryptographic digital signature to your outgoing emails. The sending mail server signs the email with a private key, and the receiving server uses the public key published in your domain's DNS to verify the signature.

If the signature is valid, it proves two things: the email genuinely originated from the domain, and the message content was not altered in transit. DKIM solves the forwarding limitations of SPF, but on its own, it does not dictate what receiving servers should do if verification fails.

What Is DMARC and How Does It Work?

Domain-based Message Authentication, Reporting, and Conformance (DMARC) bridges the gap between SPF and DKIM. It introduces alignment rules and policy instructions.

Identifier Alignment

For an email to pass DMARC, it must achieve "alignment" with either SPF, DKIM, or both. Alignment means the domain found in the visible "From" header of the email matches the domain validated by SPF (the Return-Path domain) or DKIM (the d= tag in the signature).

DMARC Policy Actions

When an email fails DMARC alignment, the DMARC record instructs the receiving server on what action to take via the p= tag:

  • p=none (Monitoring): The email is delivered normally, but the receiving server sends XML-formatted aggregate reports back to the domain owner. This is the mandatory starting phase.
  • p=quarantine (Isolation): The email fails alignment and is treated with suspicion, typically landing in the recipient's spam or junk folder.
  • p=reject (Blocking): The email is outright rejected at the SMTP level, ensuring it never reaches the recipient in any folder.

Step-by-Step Guide to Setting Up a DMARC Record

Implementing DMARC should always be done gradually to avoid accidentally blocking your own legitimate mail flows.

Step 1: Ensure SPF and DKIM Are Active

Never publish a DMARC policy without first configuring and verifying your SPF and DKIM records. Check your DNS provider to confirm both protocols are operational for your domain.

Step 2: Establish a Reporting Email Address

DMARC generates valuable feedback reports. Create a dedicated mailbox, such as dmarc-reports@example.com, or use a third-party monitoring service to collect these XML files.

Step 3: Construct Your DMARC TXT Record

A basic DMARC record starts in monitoring mode. Create a TXT record with the hostname _dmarc.example.com.

Here is an example of a starting policy record:

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; pct=100
  • v=DMARC1: Specifies the protocol version.
  • p=none: Sets the policy to monitoring only.
  • rua=mailto:...: Defines where aggregate reports are sent.
  • pct=100: Applies the policy to 100% of messages.

Step 4: Publish the Record in DNS

Log into your domain registrar or DNS hosting provider. Add a new DNS record with the following parameters:

  • Type: TXT
  • Name / Host: _dmarc (or _dmarc.example.com depending on your DNS provider's interface)
  • Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com;
  • TTL: 3600 seconds (or default)

Step 5: Analyze Reports and Transition Policies

Monitor your incoming XML reports for a few weeks. Identify any third-party services sending mail on your behalf that lack proper SPF or DKIM setup. Once all legitimate mail sources are fully aligned, update your policy tag from p=none to p=quarantine. After confirming zero disruptions to legitimate mail, upgrade your policy to p=reject for maximum security.

Verifying Your DMARC Implementation

After publishing your DNS record, you need to verify that it is syntactically correct and accessible to mail servers across the internet. You can easily test your setup and view real-time diagnostics by using the dmarc checker to ensure your DNS syntax and policies are properly configured.

DMARC Implementation Checklist

  • Confirm SPF record is published and lists all sending IPs.
  • Confirm DKIM is enabled and signing outgoing emails.
  • Create a dedicated inbox for receiving DMARC XML reports.
  • Publish initial p=none DMARC TXT record under _dmarc.example.com.
  • Review reports for at least 2 to 4 weeks to identify legitimate mail sources.
  • Fix any SPF or DKIM alignment failures found in the reports.
  • Update DMARC policy from p=none to p=quarantine.
  • Upgrade policy to p=reject after stable quarantine performance.

Frequently asked questions

What happens if I skip setting up SPF and DKIM before adding DMARC?

If SPF and DKIM are not configured, all of your outbound emails will fail DMARC alignment. If your DMARC policy is set to quarantine or reject, your legitimate emails will be marked as spam or blocked entirely, stopping your email communication.

How long should I stay on the p=none monitoring policy?

It is recommended to remain on `p=none` for at least two to four weeks. This timeframe ensures you capture mail streams that occur infrequently, such as monthly newsletters, password resets, or automated transactional alerts.

What are DMARC aggregate reports (rua)?

Aggregate reports are XML files sent daily by receiving mail servers to the email address specified in your DMARC record's `rua` tag. They contain summary statistics about message volumes, IP addresses attempting to send mail as your domain, and the pass/fail results of SPF and DKIM checks.

Can subdomains have a different DMARC policy than the root domain?

Yes. Subdomains can have their own distinct DMARC records published under `_dmarc.subdomain.example.com`. If a subdomain does not have its own DMARC record, it will inherit the DMARC policy of the parent domain if the parent record includes the `sp=` tag.

Does DMARC protect against inbound phishing attacks?

No. DMARC is designed exclusively to protect your own domain from being spoofed by unauthorized outbound senders. It does not stop malicious emails sent from other domains from landing in your users' inboxes.

Free tools