DMARC passes when at least one supported authentication path both passes and aligns with the visible From domain. A message can therefore have a passing SPF result yet fail DMARC if the authenticated domain belongs to an unrelated service.
Move from visibility to enforcement
- List every service that sends using the domain.
- Configure aligned DKIM wherever possible.
- Publish a valid reporting address and protect it from overload.
- Review aggregate reports for genuine and unauthorised sources.
- Correct gaps before progressing from
p=noneto quarantine or reject. - Continue monitoring after enforcement.
DMARC is not a one-time DNS switch. New suppliers, forgotten applications and forwarding paths can change the results, so policy must be accompanied by ownership and regular review.
See our DMARC guide for syntax and AuthSMTP considerations.
Inventory all legitimate senders, begin with monitored reporting and enforce only after alignment gaps are resolved.
Review a recent DMARC aggregate report and account for every source sending mail that uses your visible From domain.
