Configure DMARC
Publish DMARC at monitoring policy and validate reporting.
Objective
Authenticate a sending domain
Establish SPF, DKIM, and DMARC for a sending domain.
Starting state
SPF and DKIM are publishing; DMARC missing or not yet monitored
Prerequisites
- SPF and DKIM in place for known senders
- Mailbox or service to receive aggregate reports
Estimated time
1–2 hours
Difficulty
intermediate
Required access
- DNS
- ESP or MTA admin
Inputs
- Domain
- rua reporting address
- Initial policy (usually p=none)
Step-by-step instructions
- Stand up reportingCreate a rua destination (mailbox or DMARC report processor) that can receive aggregate XML.
- Publish p=noneAdd a DMARC TXT at _dmarc. Example (replace addresses): v=DMARC1; p=none; rua=mailto:dmarc@example.com
- Collect and review reportsWait for aggregate data and identify unauthorized or failing sources before tightening policy. Next workflow when clean: Move DMARC from none to quarantine or reject.
- Confirm alignment on testsSend test messages and verify DMARC=pass with SPF or DKIM alignment. Related Solve: DMARC alignment failure; DMARC reports not arriving.
Verification
- _dmarc resolves
- Reports arrive
- Known good senders show DMARC pass
Common mistakes
- Enforcing before reports are understood
- rua pointing at an unmonitored address
- Use a third-party report analyzer or self-managed rua?
- Relaxed vs strict alignment for the first publish?
Rollback / recovery
- Keep or return to p=none; fix failing sources before any quarantine/reject
Expected outcome
DMARC monitors authentication with reporting enabled and no premature enforcement.
When to escalate
- Production mail impacted unexpectedly