DMARC Engine
Home/Free tools/DMARC Setup Wizard
Free tool · DMARC

DMARC Setup Wizard

Build a safe, staged DMARC rollout plan from p=none to p=reject.

DMARC enforcement done in one jump breaks legitimate mail. The safe way is staged: you start at p=none, which changes nothing about delivery but switches on aggregate reports so you can see every source sending mail as you. Once those reports show your genuine mail is fully aligned, you tighten to p=quarantine on a slowly rising percentage, watch again, then finish at p=reject. This wizard builds that staged plan for your domain, with the exact record to publish at each step, how long to wait, and what to confirm before you advance. Enter a domain and we will detect where you already are and start the plan from there. Everything runs in your browser; nothing you type is stored.

If you give a domain we look up its live DMARC record and start the plan from your real starting point. Leave it blank for a generic from-scratch plan.
Where mailbox providers send the daily XML reports you will read between stages. A dedicated mailbox or a DMARC monitoring inbox is ideal. The whole staged method depends on actually reading these.
This sets how long to monitor at each stage and how gently to ramp the quarantine percentage. The more independent senders you have, the longer you watch before tightening, because there are more legitimate sources that must align first.

The records below are real and ready to publish. Advance between stages only when the reports confirm it; the dwell times are minimums, not deadlines.

The DMARC Setup Wizard helps you build a staged rollout plan for a DMARC record (RFC 7489) so you move from monitoring to full enforcement without quietly dropping legitimate mail. Rather than publishing p=reject on day one, the wizard sequences the policy changes, the alignment settings and the reporting addresses you need at each step.

Why a staged rollout matters

DMARC tells receivers what to do when a message fails both SPF and DKIM alignment. Jump straight to enforcement and any forgotten sending source, such as a CRM, an invoicing platform or a payroll tool, can have its mail quarantined or rejected. A staged plan lets you watch aggregate (RUA) reports first, fix each source, then tighten the policy with confidence.

How to read and act on the plan

The wizard generates the TXT record for each phase. A typical sequence is:

  • Phase 1, p=none: publish with rua so you collect reports without affecting delivery. Use this to discover every legitimate sender.
  • Phase 2, p=quarantine: often with pct= set below 100 to ramp gradually, sending failing mail to spam while you confirm SPF and DKIM are aligned.
  • Phase 3, p=reject: the goal state, where spoofed mail is refused outright.

Set sp= to control subdomains and adkim/aspf to s only when you need strict alignment. Work through the reports between phases using our enforcement guide. If you would rather not manage the ramp yourself, the DMARC Engine done-for-you service runs it for you and watches the reports.

Frequently asked questions

How long should I stay at p=none before enforcing?

Stay at p=none long enough to see a full business cycle of sending, usually two to four weeks, so monthly senders and seasonal tools appear in your RUA reports. Only move on once every legitimate source is authenticating and aligned.

What does the pct tag do during rollout?

The pct tag applies your policy to only a percentage of failing mail, so p=quarantine; pct=25 quarantines a quarter of failures and treats the rest as p=none. It lets you ramp enforcement gradually and watch for fallout before going to 100%.

Do I need a separate DMARC record for subdomains?

Not necessarily. The sp tag on your organisational record sets the policy inherited by subdomains, so sp=reject covers them. Publish a dedicated record on a subdomain only when it needs different settings or its own reporting.

Should I configure ruf forensic reports?

The ruf tag requests per-message failure reports, but most large receivers no longer send them for privacy reasons, so they are optional. Aggregate rua reports are the ones that drive a safe rollout.

Can two DMARC records coexist during the change?

No. A domain must publish exactly one DMARC TXT record at _dmarc.yourdomain; if two are found, receivers ignore DMARC entirely. When you move to the next phase, edit the existing record rather than adding a second one.

What if mail starts failing after I enforce?

Roll the policy back to p=none or lower the pct, then check your reports to find the unaligned source. Fix its SPF or add DKIM signing for it before tightening again.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.