DMARC
19 articles
How to reach DMARC p=reject without breaking email
The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.
Read more
Navigating DMARC Alignment with Variable IP Pools in Cloud Email Services
Cloud email services' variable IP pools can cause DMARC alignment issues, affecting email delivery, a common problem for customers using services like Amazon Web Services
Read more
DMARC Alignment Pitfalls with Load Balancer IP Rotation
Load balancer IP rotation can cause DMARC alignment issues, impacting email deliverability, proper management is key to maintaining alignment
Read more
DMARC Alignment for Domains with Mixed IPv4 and IPv6 Mail Infrastructure
Achieving DMARC alignment is challenging in dual-stacked environments, this article provides solutions for domains with mixed IPv4 and IPv6 mail infrastructure
Read more
DMARC Alignment Pitfalls with Multi-Tenant ESPs
DMARC alignment challenges arise with multi-tenant ESPs, causing email deliverability issues, a common problem when using shared sending infrastructure
Read more
DMARC, SPF, and DKIM for Multi-Brand Companies
Multi-brand companies can improve email deliverability with DMARC, SPF, DKIM, preventing spam and phishing, and protecting their reputation. Proper implementation is crucial for seamless communication across brands
Read more
DMARC and Third-Party Service Onboarding: A Step-by-Step Guide to Secure Delegation
DMARC prevents email spoofing and phishing attacks by verifying email authenticity, enabling secure third-party service onboarding. This guide provides a step-by-step approach to secure delegation
Read more
DMARC and Dynamic DNS: Authentication Challenges for Home Workers and Small Offices
DMARC is crucial for email authentication, working with SPF and DKIM to verify email authenticity, but poses challenges for home workers and small offices using Dynamic DNS. DMARC helps organisations like Barclays prevent cybercriminals from sending fake emails
Read more
DMARC and Subdomain Delegation for Franchises and Multi-Tenant Systems
DMARC helps organisations secure email authentication, particularly for franchises and multi-tenant systems. It ensures only authorised emails are sent from their domain
Read more
ARC: Authenticated Received Chain explained
Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.
Read more
Why p=none gives a false sense of security
A DMARC record at p=none watches your domain but blocks nothing. Here is how to tell whether you are actually protected, and the safe path to enforcement.
Read more
DMARC alignment explained, with examples
A message can pass SPF and verify DKIM yet still fail DMARC. The reason is alignment. This guide explains SPF and DKIM alignment, relaxed versus strict mode, and the exact DMARC pass rule, with five worked examples of messages that pass and fail.
Read more
Ten common DMARC mistakes and how to avoid them
The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.
Read more
The DMARC pct tag and sampling, explained
The DMARC pct tag samples how often your policy is applied to failing mail, pushing the remainder down one level. Here is why pct=0 is a downgrade trap, how receivers actually apply the sample, and how to ramp pct safely from p=none to a full p=reject.
Read more
p=none vs quarantine vs reject
The three DMARC policies compared: what p=none, p=quarantine and p=reject each tell receivers to do with failing mail, and how to progress between them safely without breaking your own email.
Read more
The DMARC record explained, tag by tag
A plain-English reference to every tag in a DMARC record: v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf and ri. What each one does, the exact syntax it expects and the sensible default to reach for.
Read more
DMARC aggregate vs forensic reports
DMARC sends two kinds of feedback: aggregate (rua) reports and forensic (ruf) reports. They answer different questions and carry very different privacy risks. This guide explains exactly what each contains, why forensic reports have all but vanished, the data-protection considerations on both sides, and how to turn the aggregate data into a safe path from p=none to p=reject.
Read more
Why forwarding breaks email authentication
Forwarding almost always breaks SPF and sometimes breaks DKIM too. Here is what survives a forwarding hop, why DKIM is the mechanism that carries your authentication through, how DMARC's one-aligned-pass rule copes, and where ARC rescues mailing-list mail.
Read more
Publishing DMARC, SPF and DKIM on common DNS hosts
Exact steps to publish SPF, DMARC and DKIM on Cloudflare, GoDaddy, Namecheap and AWS Route 53, plus the two gotchas that break most setups: TXT chunking on long DKIM keys and CNAME coexistence at the apex.
Read more