DMARC (Domain-based Message Authentication, Reporting and Conformance) allows domain owners to define how receiving mail servers should handle messages that fail email authentication checks.
A DMARC policy is configured using the p= tag within the DMARC record. There are three available policy options:
p=nonep=quarantinep=reject
Each option provides a different level of protection against email spoofing and phishing attacks.
Table of Contents
DMARC Monitoring Mode (p=none)
The p=none policy is used for monitoring purposes.
Example:
v=DMARC1; p=none; rua=mailto:[email protected]; When this policy is enabled:
- SPF and DKIM checks are still performed.
- DMARC reports can be generated.
- No action is taken against messages that fail DMARC validation.
Messages that fail authentication are delivered normally, allowing administrators to review DMARC reports and identify legitimate email sources before enforcing stricter policies.
When to Use p=none
This policy is commonly used:
- During the initial DMARC deployment phase
- To collect DMARC reports
- To identify misconfigured email services
- Before moving to stricter enforcement
DMARC Quarantine Mode (p=quarantine)
The p=quarantine policy instructs receiving mail servers to treat messages that fail DMARC validation as suspicious.
Example:
v=DMARC1; p=quarantine; rua=mailto:[email protected]; When a message fails DMARC checks:
- It is typically placed in the Spam or Junk folder.
- It may be marked as suspicious.
- It is usually not delivered directly to the recipient’s inbox.
The exact handling depends on the recipient’s email provider.
When to Use p=quarantine
This policy is useful when:
- You want stronger protection against spoofing.
- You are confident that legitimate email sources are properly configured.
- You want to reduce the risk of phishing while still allowing failed messages to be reviewed.
DMARC Reject Mode (p=reject)
The p=reject policy provides the highest level of DMARC enforcement.
Example:
v=DMARC1; p=reject; rua=mailto:[email protected]; When a message fails DMARC validation:
- The receiving server is instructed to reject it.
- The message is not delivered to the inbox.
- The message is typically not delivered to the Spam folder either.
As a result, unauthorized messages pretending to come from your domain are blocked before reaching the recipient.
When to Use p=reject
This policy is generally recommended when:
- SPF and DKIM are fully configured.
- All legitimate sending services have been identified.
- DMARC reports confirm that valid email traffic is passing authentication successfully.
Comparing DMARC Policies
| Policy | Failed Messages |
|---|---|
p=none | Monitored only, no action taken |
p=quarantine | Usually sent to Spam or Junk folders |
p=reject | Rejected and not delivered |
Recommended Deployment Approach
Many organizations implement DMARC gradually:
- Start with
p=noneto monitor email traffic. - Move to
p=quarantineonce legitimate senders are properly configured. - Switch to
p=rejectwhen authentication is working consistently across all email sources.
This staged approach helps minimize the risk of legitimate messages being affected.
Summary
DMARC offers three policy levels. p=none monitors email traffic without enforcement, p=quarantine directs suspicious messages to spam folders, and p=reject blocks messages that fail authentication entirely. Choosing the appropriate policy depends on your email infrastructure and the level of protection you want to provide against spoofing and phishing attacks.