DMARC tells receiving servers what to do with mail that claims to be from your domain but fails authentication, and asks them to send you reports.
Before you start
Set up SPF and DKIM first. DMARC builds on them. How to set up an SPF record How to enable DKIM in DirectAdmin
A safe first record
Add a TXT record in Account Manager then DNS Management:
| Field | Value |
|---|---|
| Name | _dmarc |
| Type | TXT |
| Value | v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk |
p=none means monitor only: nothing is blocked. Create the dmarc@ mailbox (or use an existing address) to receive reports.
The tags
| Tag | Meaning |
|---|---|
v=DMARC1 | Required first |
p= | Policy: none, quarantine (to spam) or reject |
rua= | Where daily aggregate reports go |
pct= | Percentage of failing mail the policy applies to |
sp= | Policy for subdomains |
adkim= / aspf= | Alignment strictness: r relaxed (default) or s strict |
Alignment in plain terms
DMARC passes when SPF or DKIM passes for the same domain as the From address. Mail from you@yourdomain.co.uk, signed with DKIM for yourdomain.co.uk, passes. A newsletter tool sending “from” your domain but signing with its own domain doesn’t, until you set up that tool’s custom domain authentication.
Tightening the policy
- Run
p=nonefor a few weeks and read the reports. They’re XML; a free DMARC report viewer makes them readable. - Fix any legitimate service that fails.
- Move to
p=quarantine, optionally withpct=25at first. - When nothing legitimate fails, consider
p=reject.
Important: Jumping straight to p=reject can block your own legitimate mail from services you’d forgotten about.