DMARC p=none vs quarantine vs reject
The DMARC policy tag tells receivers what to do with mail that fails authentication.
p=none changes nothing and only collects reports, p=quarantine sends
failures to spam, and p=reject refuses them outright. Start at none, read the reports,
and move up only once every legitimate sender passes.
What DMARC actually evaluates
SPF and DKIM each answer a narrow question: did this message come from an authorised server, and does it carry a valid signature. Neither looks at the From address a recipient sees. DMARC adds that missing link, called alignment: the domain that passed SPF or DKIM must match the domain in the visible From header.
A message passes DMARC if either SPF or DKIM passes and is aligned. Both do not have to pass. That matters in practice, because forwarding routinely breaks SPF while leaving DKIM intact — a domain relying on SPF alone sees forwarded mail fail, which is a common reason to think DMARC is too risky when the real problem is a missing DKIM signature.
p=none — monitoring
No effect on delivery whatsoever. A message that fails is handled exactly as it would be without
DMARC. What none does is start the flow of aggregate reports to the address in your
rua tag.
Those reports are the entire point. They list every source sending mail as your domain, with pass and fail counts. This is where almost everyone discovers a service they had forgotten — the invoicing tool, the CRM, the helpdesk, a marketing platform someone set up two years ago. You cannot safely enforce a policy until you have seen that list, which is why none is a stage and not a destination.
A DMARC record without a rua address is the one genuinely pointless configuration. It
changes nothing and tells you nothing.
p=quarantine — spam folder
Failing mail is delivered to the spam folder rather than the inbox. It is the useful middle step: a mistake is recoverable, because the recipient can still find the message, but spoofed mail stops reaching the inbox.
The pct tag applies a policy to a percentage of failing mail. Setting
p=quarantine; pct=25 quarantines a quarter and leaves the rest alone, which lets you
watch the effect at limited blast radius. Note that pct is honoured for quarantine and
reject but has no meaning under none.
p=reject — refused at the door
The receiving server refuses the message during the SMTP conversation. It does not reach spam; it does not arrive at all. This is the only policy that actually stops someone spoofing your domain, and it is the goal for any domain that matters.
It is also unforgiving. A sender you have not authorised has its mail destroyed, not delayed, and you will usually hear about it from the recipient rather than from a report. Going straight to reject on a domain you have not surveyed is the single most common way to break your own invoicing or support email.
A sensible progression
Publish p=none with a rua address and leave it for two to four weeks. Read the reports
until you recognise every sending source and each one passes SPF or DKIM with alignment. Fix what
fails — usually a missing DKIM signature on a third-party platform. Move to
p=quarantine, optionally with pct, and watch for another couple of weeks. Then reject.
Rushing this does not get you protected sooner; it gets you a policy you have to roll back.
How to check this
The SPF, DKIM and DMARC generator builds the record with your chosen policy, alignment mode and report addresses, and warns when you select reject at full percentage without having been through the earlier stages. Since DMARC depends on SPF being valid in the first place, it is worth confirming you are inside the SPF 10 DNS lookup limit before you enforce anything.
Frequently asked questions
Should I start DMARC at p=reject?
No. Start at p=none with a rua address and read the aggregate reports until every legitimate sender passes SPF or DKIM with alignment. Going straight to reject destroys mail from services you have not authorised yet, and you will hear about it from recipients rather than from a report.
Do SPF and DKIM both need to pass for DMARC?
No, either one is enough, provided it is aligned with the visible From domain. This matters because forwarding routinely breaks SPF while leaving DKIM intact, so a domain relying on SPF alone sees forwarded mail fail.
What does the pct tag do?
It applies the policy to a percentage of failing mail, so p=quarantine; pct=25 quarantines a quarter and leaves the rest alone. It is honoured for quarantine and reject, and has no meaning under p=none.