Updated: 28 September 2026 · Applies to: DNS for domains that send email
DMARC ties SPF and DKIM together. It tells receivers what to do with mail that claims to come from your domain but fails authentication, and it asks them to send you reports. Gmail, Yahoo and Microsoft all expect a DMARC record from bulk senders (Gmail, Yahoo and Microsoft requirements for bulk senders: a checklist). This guide publishes DMARC for the domains you send from and explains how to move to a stricter policy safely.
Before you start
- SPF (How to write an SPF record for a server with several IP addresses?) and DKIM (How to set up DKIM signing with OpenDKIM and Postfix for several domains?) work and pass in your test messages.
- Create a mailbox that receives the reports, for example
dmarc-reports@example.com. Reports are automatic messages with compressed XML attachments.
1. Publish a monitoring policy
Add a TXT record named _dmarc.example.com with this value:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r
p=none: receivers take no action, but they send you reports.rua: where the daily reports go.adkim=r; aspf=r: relaxed alignment, so that a subdomain of your domain in the DKIM or SPF domain still counts.
Check: dig +short TXT _dmarc.example.com. On cPanel hosting see How to Add an MX Record in cPanel DNS Zone Editor for how to add records.
2. Read the reports
After a day or two you receive reports from large providers. They list which IP addresses sent mail with your domain and whether SPF and DKIM passed. Every legitimate sender must pass and align. Fix what fails: a forgotten server in SPF, a program that does not sign, a newsletter tool with its own domain. Free and paid report viewers turn the XML into tables; point rua to their address if you use one.
3. Tighten the policy step by step
p=nonefor several weeks, until all legitimate mail passes.p=quarantine: failing mail goes to spam. Optionally usepct=25first to apply it to a quarter of the mail, then raise it.p=reject: failing mail is refused. Use it when reports show no legitimate failures.
Alignment in one minute
DMARC passes when SPF or DKIM passes and the domain that passed matches the domain in the visible From address. When you sign with DKIM using the same domain as the From address (as in How to set up DKIM signing with OpenDKIM and Postfix for several domains?), DKIM alone gives you alignment.
Subdomains for different mail
If you send newsletters from news.example.com, publish a DMARC record for that name too, or set sp= in the main record to define the policy for subdomains. Keeping newsletters on a subdomain separates their reputation from your everyday business mail.
Common mistakes
- Going to
rejectbefore you have read the reports. - A report address at another domain: that domain must permit it with a special DNS record. Use an address in the same domain.
- Two DMARC records.
- Forgetting that forwarded mail can fail SPF; DKIM survives forwarding, which is one more reason to sign everything.
Frequently asked questions
Is DMARC required?
Ucartz's Acceptable Use Policy recommends it, and Gmail, Yahoo and Microsoft require it from bulk senders.
What about Google Workspace mailboxes on the same domain?
Add Google's SPF and DKIM as well; see How to set up DMARC for Google Workspace?.
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
