DMARC Engine
Home/Blog/DMARC
Blog

DMARC

19 articles

1 June 2026 · 11 min read

How to reach DMARC p=reject without breaking email

The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.

Read more
29 July 2026 · 36 min read

Navigating DMARC Alignment with Variable IP Pools in Cloud Email Services

Cloud email services' variable IP pools can cause DMARC alignment issues, affecting email delivery, a common problem for customers using services like Amazon Web Services

Read more
28 July 2026 · 34 min read

DMARC Alignment Pitfalls with Load Balancer IP Rotation

Load balancer IP rotation can cause DMARC alignment issues, impacting email deliverability, proper management is key to maintaining alignment

Read more
27 July 2026 · 37 min read

DMARC Alignment for Domains with Mixed IPv4 and IPv6 Mail Infrastructure

Achieving DMARC alignment is challenging in dual-stacked environments, this article provides solutions for domains with mixed IPv4 and IPv6 mail infrastructure

Read more
25 July 2026 · 37 min read

DMARC Alignment Pitfalls with Multi-Tenant ESPs

DMARC alignment challenges arise with multi-tenant ESPs, causing email deliverability issues, a common problem when using shared sending infrastructure

Read more
19 July 2026 · 38 min read

DMARC, SPF, and DKIM for Multi-Brand Companies

Multi-brand companies can improve email deliverability with DMARC, SPF, DKIM, preventing spam and phishing, and protecting their reputation. Proper implementation is crucial for seamless communication across brands

Read more
18 July 2026 · 36 min read

DMARC and Third-Party Service Onboarding: A Step-by-Step Guide to Secure Delegation

DMARC prevents email spoofing and phishing attacks by verifying email authenticity, enabling secure third-party service onboarding. This guide provides a step-by-step approach to secure delegation

Read more
17 July 2026 · 40 min read

DMARC and Dynamic DNS: Authentication Challenges for Home Workers and Small Offices

DMARC is crucial for email authentication, working with SPF and DKIM to verify email authenticity, but poses challenges for home workers and small offices using Dynamic DNS. DMARC helps organisations like Barclays prevent cybercriminals from sending fake emails

Read more
16 July 2026 · 40 min read

DMARC and Subdomain Delegation for Franchises and Multi-Tenant Systems

DMARC helps organisations secure email authentication, particularly for franchises and multi-tenant systems. It ensures only authorised emails are sent from their domain

Read more
20 June 2026 · 12 min read

ARC: Authenticated Received Chain explained

Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.

Read more
15 June 2026 · 11 min read

Why p=none gives a false sense of security

A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.

Read more
11 June 2026 · 14 min read

DMARC alignment explained, with examples

A message can pass SPF and verify DKIM yet still fail DMARC. The reason is alignment. This guide explains SPF and DKIM alignment, relaxed versus strict mode, and the exact DMARC pass rule, with five worked examples of messages that pass and fail.

Read more
10 June 2026 · 12 min read

Ten common DMARC mistakes and how to avoid them

The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.

Read more
6 June 2026 · 15 min read

The DMARC pct tag and sampling, explained

The DMARC pct tag samples how often your policy is applied to failing mail, pushing the remainder down one level. Here is why pct=0 is a downgrade trap, how receivers actually apply the sample, and how to ramp pct safely from p=none to a full p=reject.

Read more
5 June 2026 · 12 min read

p=none vs quarantine vs reject

The three DMARC policies compared: what p=none, p=quarantine and p=reject each tell receivers to do with failing mail, and how to progress between them safely without breaking your own email.

Read more
4 June 2026 · 15 min read

The DMARC record explained, tag by tag

A plain-English reference to every tag in a DMARC record: v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf and ri. What each one does, the exact syntax it expects and the sensible default to reach for.

Read more
2 June 2026 · 12 min read

DMARC aggregate vs forensic reports

DMARC sends two kinds of feedback: aggregate (rua) reports and forensic (ruf) reports. They answer different questions and carry very different privacy risks. This guide explains exactly what each contains, why forensic reports have all but vanished, the data-protection considerations on both sides, and how to turn the aggregate data into a safe path from p=none to p=reject.

Read more
26 May 2026 · 13 min read

Why forwarding breaks email authentication

Forwarding almost always breaks SPF and sometimes breaks DKIM too. Here is what survives a forwarding hop, why DKIM is the mechanism that carries your authentication through, how DMARC's one-aligned-pass rule copes, and where ARC rescues mailing-list mail.

Read more
21 May 2026 · 13 min read

Publishing DMARC, SPF and DKIM on common DNS hosts

Exact steps to publish SPF, DMARC and DKIM on Cloudflare, GoDaddy, Namecheap and AWS Route 53, plus the two gotchas that break most setups: TXT chunking on long DKIM keys and CNAME coexistence at the apex.

Read more