DMARC Engine
Home/Glossary/DMARC policy (p=none/quarantine/reject)
Glossary

DMARC policy (p=none/quarantine/reject)

The p= tag in a DMARC record tells receivers what to do with mail that fails DMARC: monitor, quarantine or reject.

The DMARC policy is set by the p= tag in your _dmarc TXT record, defined in RFC 7489. It tells receiving mail servers what to do with messages claiming to be from your domain that fail DMARC, meaning they are not aligned through either SPF or DKIM.

There are three values. p=none takes no action and is purely for monitoring; you still receive aggregate reports but failing mail is delivered normally. p=quarantine asks receivers to treat failing mail as suspicious, typically routing it to the spam or junk folder. p=reject instructs receivers to refuse failing mail outright, which is the only policy that genuinely stops spoofing of your domain.

The goal of any DMARC rollout is to reach enforcement at p=quarantine or p=reject. Start at none, study the reports until every legitimate source is aligned, then tighten the policy, optionally using pct to ramp gradually and sp to control subdomains.

Check your current policy with our DMARC checker, and let DMARC Engine handle the done-for-you path from monitoring to safe enforcement.

Check it on your domain

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.