When implementing a DMARC policy, it is important to consider how many messages should be affected by the policy. The pct tag allows you to specify the percentage of emails that should be processed according to the DMARC policy.
This is particularly useful when introducing DMARC gradually, as it allows you to monitor the impact of the policy before applying it to all messages.
Table of Contents
What Does the pct Tag Do?
The pct parameter defines the percentage of messages that will be subject to the DMARC policy.
For example:
v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]; In this example:
- The DMARC policy is set to
quarantine. - Only 10% of messages that fail DMARC checks will be quarantined.
- The remaining messages will be handled normally by the receiving mail server.
Why Start with a Lower Percentage?
Before enforcing DMARC across all email traffic, it is common to start with a lower percentage and gradually increase it.
This approach helps:
- Identify legitimate email sources that may not be configured correctly.
- Reduce the risk of affecting valid email messages.
- Test SPF, DKIM, and DMARC alignment.
- Review DMARC reports before increasing enforcement.
Recommended Starting Values
Small Organizations
For smaller organizations, a starting value of:
pct=10 is often used.
This means approximately 10% of messages that fail DMARC validation will be quarantined.
The lower enforcement level allows administrators to monitor the effect of the policy while minimizing the risk of legitimate messages being treated as spam.
Large Organizations
For larger organizations with complex email infrastructures, a more cautious approach may be appropriate.
A value such as:
pct=1 can be used initially.
This means only about 1% of messages that fail DMARC validation will be affected by the policy.
Large organizations often use multiple email services, third-party platforms, and shared infrastructure, making it more important to identify all legitimate sending sources before increasing enforcement.
Example DMARC Record
v=DMARC1; p=quarantine; pct=10; adkim=r; aspf=r; rua=mailto:[email protected]; In this example:
| Tag | Description |
|---|---|
v=DMARC1 | DMARC version |
p=quarantine | Quarantine messages that fail DMARC |
pct=10 | Apply the policy to 10% of messages |
adkim=r | Relaxed DKIM alignment |
aspf=r | Relaxed SPF alignment |
rua= | Address for aggregate DMARC reports |
Understanding the Percentage
The pct value determines how many messages are subject to the DMARC policy.
| Value | Effect |
|---|---|
pct=100 | All failing messages are processed according to the policy |
pct=50 | Approximately half of failing messages are processed according to the policy |
pct=10 | Approximately one in ten failing messages is processed according to the policy |
pct=1 | Approximately one in one hundred failing messages is processed according to the policy |
As confidence in your email configuration increases, the percentage can be gradually raised until it reaches:
pct=100 Important Consideration
The pct parameter controls how many failing messages are affected by the DMARC policy, not how many emails are checked. All messages are still evaluated against SPF, DKIM, and DMARC rules. The percentage only determines how often the specified policy is enforced on messages that fail validation.
Summary
The DMARC pct tag allows you to gradually introduce DMARC enforcement by applying a policy such as quarantine to only a percentage of failing messages. Organizations often start with lower values, such as 1% or 10%, review DMARC reports, and then increase the percentage over time until the policy is applied to all failing messages.