DMARC Engine
Glossary

DMARC

A DNS policy that tells receivers what to do with email that fails SPF and DKIM authentication checks for your domain.

DMARC (Domain-based Message Authentication, Reporting and Conformance), defined in RFC 7489, builds on SPF and DKIM to tell receiving mail servers how to handle messages that claim to be from your domain but fail authentication.

You publish a single TXT record at _dmarc.yourdomain.com. It carries a policy in the p= tag: none (monitor only), quarantine (send to spam), or reject (block outright). A message passes DMARC when either SPF or DKIM passes and the authenticated domain aligns with the address in the visible From header.

The rua= tag requests aggregate XML reports so you can see who sends as your domain; ruf= requests forensic samples. Tags like sp= set a subdomain policy and pct= roll a policy out gradually. Only one DMARC record per domain is valid; duplicates void the policy.

DMARC stops exact-domain spoofing and is a prerequisite for BIMI. Moving from none to reject safely takes patience; DMARC Engine handles that enforcement journey for you. Check your record with the tools below.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.