DMARC Engine
Home/Blog/Tagged “p-reject”
Blog

Tagged “p-reject”

12 articles

1 June 2026 · 11 min read

How to reach DMARC p=reject without breaking email

The staged playbook to DMARC enforcement with no email outage: inventory senders, fix SPF and DKIM, ramp p=none to p=reject, and lock down subdomains.

Read more
20 June 2026 · 12 min read

ARC: Authenticated Received Chain explained

Forwarding and mailing lists break SPF and DKIM in transit, flipping a passing message to a DMARC failure. ARC, the Authenticated Received Chain, preserves the original authentication verdict across intermediaries with a signed, tamper-evident chain, so trusted forwarders can vouch for legitimate mail and you can reach p=reject without breaking list traffic.

Read more
17 June 2026 · 13 min read

Done-for-you DMARC enforcement: how the managed path to p=reject works

Reaching p=reject is not the hard part. Anyone can change one DNS record from p=none to p=reject in thirty seconds. The hard part is reaching p=reject without silently dropping legitimate mail: the invoice from.

Read more
10 June 2026 · 12 min read

Ten common DMARC mistakes and how to avoid them

The configuration and rollout mistakes that most often break mail or leave domains exposed, from jumping straight to p=reject to ignoring report drift, and exactly how to avoid each one.

Read more
9 June 2026 · 11 min read

Protecting parked and no-mail domains

Domains that never send mail are the easiest to secure and the most commonly left wide open. Here is how to lock down parked, legacy and campaign domains with SPF -all, DMARC p=reject and a null MX so they cannot be spoofed, with zero deliverability risk.

Read more
7 June 2026 · 12 min read

DMARC for Microsoft 365

A practical, ordered guide to email authentication on Microsoft 365: build a complete SPF record for Exchange Online, enable DKIM signing with Microsoft's two selector CNAMEs, and walk DMARC safely from p=none through quarantine to p=reject without breaking your mail.

Read more
6 June 2026 · 15 min read

The DMARC pct tag and sampling, explained

The DMARC pct tag samples how often your policy is applied to failing mail, pushing the remainder down one level. Here is why pct=0 is a downgrade trap, how receivers actually apply the sample, and how to ramp pct safely from p=none to a full p=reject.

Read more
5 June 2026 · 12 min read

p=none vs quarantine vs reject

The three DMARC policies compared: what p=none, p=quarantine and p=reject each tell receivers to do with failing mail, and how to progress between them safely without breaking your own email.

Read more
3 June 2026 · 12 min read

How invoice fraud begins with a spoofed domain

Invoice fraud usually starts with a forged sender address. Here is how exact-domain spoofing works, what DMARC at p=reject stops, and what it does not.

Read more
2 June 2026 · 12 min read

DMARC aggregate vs forensic reports

DMARC sends two kinds of feedback: aggregate (rua) reports and forensic (ruf) reports. They answer different questions and carry very different privacy risks. This guide explains exactly what each contains, why forensic reports have all but vanished, the data-protection considerations on both sides, and how to turn the aggregate data into a safe path from p=none to p=reject.

Read more
1 June 2026 · 9 min read

Subdomain policy: the DMARC sp tag

An enforced root domain at p=reject protects exactly one address and can leave every subdomain spoofable. Here is what the DMARC sp tag does, the inheritance trap that catches teams mid-migration, and how to close the gap safely without bouncing legitimate subdomain mail.

Read more
25 May 2026 · 11 min read

Lookalike and cousin domains

Attackers register confusable domains that authenticate perfectly and slip past your defences, because your DMARC policy protects only the exact name it is published under. Here is how homoglyph and cousin domains work, the precise reason a p=reject policy cannot touch them, and the layered plan that actually defends your brand.

Read more