How to set up a DMARC record

Publish a DMARC record for your domain: a safe starting policy, what each tag means, reading reports and moving towards quarantine or reject.

How-to guideIntermediate2 min readUpdated

DMARC tells receiving servers what to do with mail that claims to be from your domain but fails authentication, and asks them to send you reports.

Before you start

Set up SPF and DKIM first. DMARC builds on them. How to set up an SPF record How to enable DKIM in DirectAdmin

A safe first record

Add a TXT record in Account Manager then DNS Management:

FieldValue
Name_dmarc
TypeTXT
Valuev=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk

p=none means monitor only: nothing is blocked. Create the dmarc@ mailbox (or use an existing address) to receive reports.

The tags

TagMeaning
v=DMARC1Required first
p=Policy: none, quarantine (to spam) or reject
rua=Where daily aggregate reports go
pct=Percentage of failing mail the policy applies to
sp=Policy for subdomains
adkim= / aspf=Alignment strictness: r relaxed (default) or s strict

Alignment in plain terms

DMARC passes when SPF or DKIM passes for the same domain as the From address. Mail from you@yourdomain.co.uk, signed with DKIM for yourdomain.co.uk, passes. A newsletter tool sending “from” your domain but signing with its own domain doesn’t, until you set up that tool’s custom domain authentication.

Tightening the policy

  1. Run p=none for a few weeks and read the reports. They’re XML; a free DMARC report viewer makes them readable.
  2. Fix any legitimate service that fails.
  3. Move to p=quarantine, optionally with pct=25 at first.
  4. When nothing legitimate fails, consider p=reject.

Important: Jumping straight to p=reject can block your own legitimate mail from services you’d forgotten about.

Popular

Tip: press / to search from any pageSee all results