DNS, email and security
DMARC
DMARC is a DNS policy that tells receiving mail servers what to do with email that fails SPF or DKIM checks, and where to send reports about it.
What DMARC means in practice
A DMARC record can ask receivers to do nothing but report (p=none), to put failing mail in spam (p=quarantine) or to reject it (p=reject). The reports show who is sending mail in your name.
It builds on spf record and dkim: mail passes when one of them passes and matches the domain in the visible From address.
Why it matters
DMARC with a quarantine or reject policy is the main way to stop others from sending convincing mail from your domain.
Try it
- Domain Health Check Expiry date, transfer lock, DNS, SPF and DMARC email security, and blocklists for a .com.
Related terms
- SPF record An SPF record is a DNS entry that lists the servers allowed to send email for a domain, so receivers can spot mail that is faked.
- DKIM DKIM adds a digital signature to outgoing email, checked against a public key published in the sender's DNS, so receivers can tell the message was not altered.
- DNS (Domain Name System) DNS is the internet's phone book: it turns a domain name into the addresses and settings that browsers and mail servers need to reach it.