The DMARC policy is set by the p= tag in your _dmarc TXT record, defined in RFC 7489. It tells receiving mail servers what to do with messages claiming to be from your domain that fail DMARC, meaning they are not aligned through either SPF or DKIM.
There are three values. p=none takes no action and is purely for monitoring; you still receive aggregate reports but failing mail is delivered normally. p=quarantine asks receivers to treat failing mail as suspicious, typically routing it to the spam or junk folder. p=reject instructs receivers to refuse failing mail outright, which is the only policy that genuinely stops spoofing of your domain.
The goal of any DMARC rollout is to reach enforcement at p=quarantine or p=reject. Start at none, study the reports until every legitimate source is aligned, then tighten the policy, optionally using pct to ramp gradually and sp to control subdomains.
Check your current policy with our DMARC checker, and let DMARC Engine handle the done-for-you path from monitoring to safe enforcement.
Check it on your domain
- DMARC Checker: look up and validate a domain's DMARC record and policy.
- DMARC Generator: build a valid DMARC record from a simple form.
- DMARC Setup Wizard: build a safe, staged DMARC rollout plan from p=none to p=reject.