{"id":469,"date":"2025-12-18T07:56:28","date_gmt":"2025-12-18T06:56:28","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=469"},"modified":"2026-06-03T06:12:46","modified_gmt":"2026-06-03T04:12:46","slug":"cum-functioneaza-carantina-dmarc","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/","title":{"rendered":"Cum func\u021bioneaz\u0103 carantina DMARC?"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">DMARC (Domain-based Message Authentication, Reporting and Conformance) helps protect domains against email spoofing and phishing attacks by defining how receiving mail servers should handle messages that fail authentication checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>quarantine policy<\/strong> is one of the three available DMARC policies:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>p=none<\/code> \u2013 Monitor only<\/li>\n\n\n\n<li><code>p=quarantine<\/code> \u2013 Treat suspicious messages as spam<\/li>\n\n\n\n<li><code>p=reject<\/code> \u2013 Reject suspicious messages completely<\/li>\n<\/ul>\n\n\n\n<\/div>\n\n<div id=\"mybox-4127987292\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">When a domain uses <code>p=quarantine<\/code>, receiving mail servers are instructed to treat messages that fail DMARC checks as potentially suspicious rather than delivering them directly to the recipient&#8217;s inbox.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#What_Happens_When_DMARC_Quarantine_Is_Enabled\" >What Happens When DMARC Quarantine Is Enabled?<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Step_1_Check_for_a_DMARC_Record\" >Step 1: Check for a DMARC Record<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Step_2_Verify_SPF_and_DKIM\" >Step 2: Verify SPF and DKIM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Step_3_Verify_Domain_Alignment\" >Step 3: Verify Domain Alignment<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Step_4_Apply_the_DMARC_Policy\" >Step 4: Apply the DMARC Policy<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Step_5_Move_the_Message_to_Spam_or_Junk\" >Step 5: Move the Message to Spam or Junk<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Why_Use_a_Quarantine_Policy\" >Why Use a Quarantine Policy?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Example\" >Example<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#When_Should_You_Use_Quarantine\" >When Should You Use Quarantine?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/how-does-dmarc-quarantine-work\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Happens_When_DMARC_Quarantine_Is_Enabled\"><\/span>What Happens When DMARC Quarantine Is Enabled?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When an email is received, the destination mail server performs a series of checks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_1_Check_for_a_DMARC_Record\"><\/span>Step 1: Check for a DMARC Record<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The receiving server looks for a DMARC record in the sender&#8217;s DNS zone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; ruf=mailto:dmarc@yourdomain.com; fo=1<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This record tells receiving servers how to handle messages that fail DMARC validation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_2_Verify_SPF_and_DKIM\"><\/span>Step 2: Verify SPF and DKIM<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The receiving server checks whether the message passes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SPF (Sender Policy Framework)<\/li>\n\n\n\n<li>DKIM (DomainKeys Identified Mail)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These mechanisms help verify that the sender is authorized to send email on behalf of the domain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_3_Verify_Domain_Alignment\"><\/span>Step 3: Verify Domain Alignment<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">DMARC also checks whether the domain used in the <strong>From<\/strong> address aligns with the domains validated through SPF or DKIM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This process is known as <strong>domain alignment<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>From: admin@yourdomain.com<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The domain in the From address should match the domain authenticated by SPF or DKIM.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_4_Apply_the_DMARC_Policy\"><\/span>Step 4: Apply the DMARC Policy<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If the message passes the required checks, it is delivered normally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the message fails DMARC validation, the receiving server applies the policy specified in the DMARC record.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>p=quarantine<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">the message is treated as suspicious.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_5_Move_the_Message_to_Spam_or_Junk\"><\/span>Step 5: Move the Message to Spam or Junk<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of delivering the message directly to the inbox, the receiving server may:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Move it to the Spam folder<\/li>\n\n\n\n<li>Move it to the Junk folder<\/li>\n\n\n\n<li>Mark it as suspicious<\/li>\n\n\n\n<li>Apply additional filtering rules<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The exact behavior depends on the recipient&#8217;s email provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike <code>p=reject<\/code>, the message is usually still delivered to the recipient&#8217;s mailbox, but not to the primary inbox.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Use_a_Quarantine_Policy\"><\/span>Why Use a Quarantine Policy?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A quarantine policy provides a balance between monitoring and strict enforcement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Benefits include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protection against email spoofing<\/li>\n\n\n\n<li>Reduced risk of phishing attacks<\/li>\n\n\n\n<li>Improved domain reputation<\/li>\n\n\n\n<li>Lower likelihood of legitimate messages being blocked completely<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Because messages are quarantined rather than rejected, administrators can monitor the impact of DMARC enforcement before moving to a stricter policy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Example\"><\/span>Example<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine an attacker attempts to send:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>admin@yourdomain.com<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">but the sending server is not authorized in your SPF record and cannot generate a valid DKIM signature.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The message will fail DMARC validation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your DMARC policy is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>p=quarantine<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">the receiving server will typically place the message in the recipient&#8217;s Spam or Junk folder instead of the inbox.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_Should_You_Use_Quarantine\"><\/span>When Should You Use Quarantine?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many organizations implement DMARC in stages:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><code>p=none<\/code> \u2013 Monitor email traffic and collect reports.<\/li>\n\n\n\n<li><code>p=quarantine<\/code> \u2013 Move suspicious messages to spam folders.<\/li>\n\n\n\n<li><code>p=reject<\/code> \u2013 Block unauthorized messages completely.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This gradual approach helps identify legitimate mail sources before enforcing stricter policies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A DMARC quarantine policy (<code>p=quarantine<\/code>) instructs receiving mail servers to treat messages that fail DMARC authentication as suspicious. Instead of being delivered directly to the inbox, these messages are typically placed in a spam or junk folder. This helps protect against spoofing and phishing attacks while reducing the risk of accidentally blocking legitimate email traffic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[62,128],"manual_kb_tag":[3113,3114,3115,3116,3117,3118,797,799,811,1671],"class_list":["post-469","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-domain-management-in-panel","manualknowledgebasecat-domains","manual_kb_tag-dmarc-quarantine","manual_kb_tag-quarantine-policy","manual_kb_tag-spf-authentication","manual_kb_tag-dkim-authentication","manual_kb_tag-domain-alignment","manual_kb_tag-sender-impersonation","manual_kb_tag-email-authentication","manual_kb_tag-dmarc","manual_kb_tag-phishing-prevention","manual_kb_tag-spoofing-prevention"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/469\/revisions"}],"predecessor-version":[{"id":9533,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/469\/revisions\/9533"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=469"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=469"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}