ValidMailbox

DMARC p=none vs quarantine vs reject

The DMARC policy tag tells receivers what to do with mail that fails authentication. p=none changes nothing and only collects reports, p=quarantine sends failures to spam, and p=reject refuses them outright. Start at none, read the reports, and move up only once every legitimate sender passes.

What DMARC actually evaluates

SPF and DKIM each answer a narrow question: did this message come from an authorised server, and does it carry a valid signature. Neither looks at the From address a recipient sees. DMARC adds that missing link, called alignment: the domain that passed SPF or DKIM must match the domain in the visible From header.

A message passes DMARC if either SPF or DKIM passes and is aligned. Both do not have to pass. That matters in practice, because forwarding routinely breaks SPF while leaving DKIM intact — a domain relying on SPF alone sees forwarded mail fail, which is a common reason to think DMARC is too risky when the real problem is a missing DKIM signature.

p=none — monitoring

No effect on delivery whatsoever. A message that fails is handled exactly as it would be without DMARC. What none does is start the flow of aggregate reports to the address in your rua tag.

Those reports are the entire point. They list every source sending mail as your domain, with pass and fail counts. This is where almost everyone discovers a service they had forgotten — the invoicing tool, the CRM, the helpdesk, a marketing platform someone set up two years ago. You cannot safely enforce a policy until you have seen that list, which is why none is a stage and not a destination.

A DMARC record without a rua address is the one genuinely pointless configuration. It changes nothing and tells you nothing.

p=quarantine — spam folder

Failing mail is delivered to the spam folder rather than the inbox. It is the useful middle step: a mistake is recoverable, because the recipient can still find the message, but spoofed mail stops reaching the inbox.

The pct tag applies a policy to a percentage of failing mail. Setting p=quarantine; pct=25 quarantines a quarter and leaves the rest alone, which lets you watch the effect at limited blast radius. Note that pct is honoured for quarantine and reject but has no meaning under none.

p=reject — refused at the door

The receiving server refuses the message during the SMTP conversation. It does not reach spam; it does not arrive at all. This is the only policy that actually stops someone spoofing your domain, and it is the goal for any domain that matters.

It is also unforgiving. A sender you have not authorised has its mail destroyed, not delayed, and you will usually hear about it from the recipient rather than from a report. Going straight to reject on a domain you have not surveyed is the single most common way to break your own invoicing or support email.

A sensible progression

Publish p=none with a rua address and leave it for two to four weeks. Read the reports until you recognise every sending source and each one passes SPF or DKIM with alignment. Fix what fails — usually a missing DKIM signature on a third-party platform. Move to p=quarantine, optionally with pct, and watch for another couple of weeks. Then reject.

Rushing this does not get you protected sooner; it gets you a policy you have to roll back.

How to check this

The SPF, DKIM and DMARC generator builds the record with your chosen policy, alignment mode and report addresses, and warns when you select reject at full percentage without having been through the earlier stages. Since DMARC depends on SPF being valid in the first place, it is worth confirming you are inside the SPF 10 DNS lookup limit before you enforce anything.

Frequently asked questions

Should I start DMARC at p=reject?

No. Start at p=none with a rua address and read the aggregate reports until every legitimate sender passes SPF or DKIM with alignment. Going straight to reject destroys mail from services you have not authorised yet, and you will hear about it from recipients rather than from a report.

Do SPF and DKIM both need to pass for DMARC?

No, either one is enough, provided it is aligned with the visible From domain. This matters because forwarding routinely breaks SPF while leaving DKIM intact, so a domain relying on SPF alone sees forwarded mail fail.

What does the pct tag do?

It applies the policy to a percentage of failing mail, so p=quarantine; pct=25 quarantines a quarter and leaves the rest alone. It is honoured for quarantine and reject, and has no meaning under p=none.