Skip to content
Back to Glossary

Authentication

Updated

DMARC (Domain-based Message Authentication, Reporting and Conformance)

Definition

DMARC is a DNS TXT record at _dmarc.yourdomain.com that tells receivers what to do with mail that claims to be from your domain but fails authentication. A message passes DMARC when SPF or DKIM passes and that domain aligns with the visible From address.

How it works

DMARC is defined in RFC 7489. A receiver takes the domain in the From header, looks up _dmarc on that domain (falling back to the organizational domain), and checks two things: did SPF pass for an aligned Return-Path domain, or did DKIM pass for an aligned d= domain. One aligned pass is enough.

Alignment is relaxed by default (adkim=r, aspf=r), so news.example.com aligns with example.com. Strict alignment (s) requires an exact match.

The p= tag sets the policy for failures: none (deliver and report), quarantine (treat as suspicious, usually spam folder) or reject (refuse at SMTP). The rua= tag receives daily aggregate XML reports listing every source sending as your domain.

Example

DMARC TXT record
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]; adkim=r; aspf=r"

Quarantine mail that fails aligned SPF and DKIM, relaxed alignment, aggregate reports to [email protected].

Why it matters

Without DMARC, anyone can send mail with your domain in the From line and receivers have no instruction to stop it. DMARC at quarantine or reject is what actually blocks direct-domain spoofing and phishing.

Since February 2024, Gmail and Yahoo require bulk senders to publish DMARC (p=none is the minimum) with From aligned to SPF or DKIM. Enforced DMARC is also a prerequisite for BIMI logos.

Best practices

  • Start with p=none and a rua= address to see every service sending as your domain.
  • Fix each legitimate source so it passes aligned DKIM (preferably) or SPF, then move to p=quarantine and finally p=reject.
  • Publish one DMARC record per name, as a TXT record. A CNAME on _dmarc or two TXT records breaks it.
  • Use sp= if subdomains need a different policy than the root. Otherwise subdomains inherit the organizational domain's policy.
  • Read aggregate reports with a parser or a DMARC service. Raw XML from dozens of receivers is not meant for humans.
DMARC policies
PolicyWhat receivers do with failing mailWhen to use it
p=noneDeliver normally, send reportsFirst weeks, while you inventory senders
p=quarantineTreat as suspicious, usually spam folderOnce legitimate mail passes aligned
p=rejectRefuse during the SMTP transactionFull enforcement against spoofing

How Lumail handles DMARC

Lumail does not create your DMARC record, because it governs every service that sends as your domain. It checks that the record exists and is valid, including inherited policies from your root domain when you send from a subdomain.

When your policy is p=none, Lumail shows a monitoring-only notice until you move to quarantine or reject. Lumail mail passes aligned DKIM and SPF once your domain verifies, so enforcing DMARC does not block it.

Check a real message with the free mail tester or the spam tester.

Frequently asked questions

Is p=none enough?

It satisfies the Gmail and Yahoo bulk sender requirement, but it does not stop spoofing: failing mail is still delivered. Treat p=none as a monitoring phase and move to quarantine or reject.

Do I need both SPF and DKIM to pass DMARC?

No. One aligned pass is enough. In practice, set up both so mail still passes when one breaks, for example SPF after forwarding.

Where do I put a DMARC record for a subdomain?

Receivers check _dmarc.sub.example.com first, then fall back to _dmarc.example.com. A record on the root covers subdomains unless you want a different policy for one of them.

What are rua and ruf?

rua= receives aggregate reports: daily XML summaries of pass and fail counts per sending IP. ruf= requests per-message failure reports, which most large mailbox providers do not send for privacy reasons.

Related terms, tools and docs

Browse every definition in the email marketing glossary.

Send your next email with Lumail.

3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.