DMARC
8 articles
What do the DMARC record tags mean?
A plain-English reference to every DMARC record tag (v, p, sp, pct, rua, ruf, fo, adkim, aspf and ri), with valid values, defaults and worked examples.
Read moreWhat is DMARC alignment and why does my mail fail it?
DMARC alignment is the rule that ties SPF or DKIM back to the visible From domain. Here is why mail can pass SPF/DKIM yet still fail DMARC, with worked examples and fixes.
Read moreWhy does forwarded email fail DMARC, and what can I do?
Forwarding breaks SPF because the relay's IP isn't in your record, but DKIM usually survives, so DMARC still passes and p=reject stays safe with proper DKIM.
Read moreHow do I check that my DMARC is working?
"Is my DMARC working?" is one of those questions that hides a second, harder one inside it: working to do what, exactly? A DMARC record can be syntactically perfect, published at the right place, and visible to the.
Read moreHow do I know it is safe to move to p=reject?
You know it is safe to move to p=reject when the evidence says so, not when a date on the calendar arrives or when you feel impatient with p=none.
Read moreIs email authentication required for HIPAA compliance?
Short answer: HIPAA does not contain a rule that says "you must publish a DMARC record." The word DMARC appears nowhere in the regulation, and neither do SPF, DKIM or BIMI.
Read moreDoes PCI DSS require DMARC?
Short answer: yes, PCI DSS version 4 names DMARC by name, and this is the first version of the standard to do so. Earlier versions of PCI DSS talked about anti-phishing in general terms and left the technology.
Read moreDo I need a DMARC record for each subdomain?
No, your organisational _dmarc record covers subdomains by default, and sp= sets their policy; add a subdomain record only for a specific exception.
Read more