Authentication
Updated
DMARC (Domain-based Message Authentication, Reporting and Conformance)
Definition
DMARC is a DNS TXT record at _dmarc.yourdomain.com that tells receivers what to do with mail that claims to be from your domain but fails authentication. A message passes DMARC when SPF or DKIM passes and that domain aligns with the visible From address.
How it works
DMARC is defined in RFC 7489. A receiver takes the domain in the From header, looks up _dmarc on that domain (falling back to the organizational domain), and checks two things: did SPF pass for an aligned Return-Path domain, or did DKIM pass for an aligned d= domain. One aligned pass is enough.
Alignment is relaxed by default (adkim=r, aspf=r), so news.example.com aligns with example.com. Strict alignment (s) requires an exact match.
The p= tag sets the policy for failures: none (deliver and report), quarantine (treat as suspicious, usually spam folder) or reject (refuse at SMTP). The rua= tag receives daily aggregate XML reports listing every source sending as your domain.
Example
Quarantine mail that fails aligned SPF and DKIM, relaxed alignment, aggregate reports to [email protected].
Why it matters
Without DMARC, anyone can send mail with your domain in the From line and receivers have no instruction to stop it. DMARC at quarantine or reject is what actually blocks direct-domain spoofing and phishing.
Since February 2024, Gmail and Yahoo require bulk senders to publish DMARC (p=none is the minimum) with From aligned to SPF or DKIM. Enforced DMARC is also a prerequisite for BIMI logos.
Best practices
- Start with p=none and a rua= address to see every service sending as your domain.
- Fix each legitimate source so it passes aligned DKIM (preferably) or SPF, then move to p=quarantine and finally p=reject.
- Publish one DMARC record per name, as a TXT record. A CNAME on _dmarc or two TXT records breaks it.
- Use sp= if subdomains need a different policy than the root. Otherwise subdomains inherit the organizational domain's policy.
- Read aggregate reports with a parser or a DMARC service. Raw XML from dozens of receivers is not meant for humans.
| Policy | What receivers do with failing mail | When to use it |
|---|---|---|
| p=none | Deliver normally, send reports | First weeks, while you inventory senders |
| p=quarantine | Treat as suspicious, usually spam folder | Once legitimate mail passes aligned |
| p=reject | Refuse during the SMTP transaction | Full enforcement against spoofing |
How Lumail handles DMARC
Lumail does not create your DMARC record, because it governs every service that sends as your domain. It checks that the record exists and is valid, including inherited policies from your root domain when you send from a subdomain.
When your policy is p=none, Lumail shows a monitoring-only notice until you move to quarantine or reject. Lumail mail passes aligned DKIM and SPF once your domain verifies, so enforcing DMARC does not block it.
Check a real message with the free mail tester or the spam tester.
Frequently asked questions
Is p=none enough?
It satisfies the Gmail and Yahoo bulk sender requirement, but it does not stop spoofing: failing mail is still delivered. Treat p=none as a monitoring phase and move to quarantine or reject.
Do I need both SPF and DKIM to pass DMARC?
No. One aligned pass is enough. In practice, set up both so mail still passes when one breaks, for example SPF after forwarding.
Where do I put a DMARC record for a subdomain?
Receivers check _dmarc.sub.example.com first, then fall back to _dmarc.example.com. A record on the root covers subdomains unless you want a different policy for one of them.
What are rua and ruf?
rua= receives aggregate reports: daily XML summaries of pass and fail counts per sending IP. ruf= requests per-message failure reports, which most large mailbox providers do not send for privacy reasons.
Related terms, tools and docs
- AuthenticationSPFSPF (Sender Policy Framework) is a DNS TXT record that lists which servers may send email using a domain in the envelope sender (Return-Path).
- AuthenticationDKIMDKIM (DomainKeys Identified Mail) is a cryptographic signature added to each email's headers.
- AuthenticationBIMIBIMI (Brand Indicators for Message Identification) is a DNS TXT record that points mailbox providers to your brand logo so they can display it next to authenticated messages.
- DeliverabilityEmail deliverabilityEmail deliverability is the ability of your emails to reach recipients' inboxes rather than bouncing or landing in spam.
- Free toolDMARC checkerRead a domain's DMARC policy, alignment and reporting tags.
- Free toolFree mail testerSend a real email and get an SPF, DKIM, DMARC and content report.
- Free toolSPF checkerLook up a domain's SPF record and count its DNS lookups.
- DocsHow to add DMARCPublish a valid _dmarc TXT record.
- DocsHow to strengthen DMARCMove from p=none to quarantine or reject.
- DocsHow to verify a sending domainEvery DNS record Lumail asks for, in order.
Browse every definition in the email marketing glossary.
Send your next email with Lumail.
3,000 emails a month free. Unlimited subscribers on every plan. Campaigns, automations and transactional email on one domain.