Every DMARC tag, and which ones matter
A DMARC record has eleven possible tags. Four of them do the work; the rest are tuning you will rarely touch.
The record lives at _dmarc.<domain> as a TXT record, with tags separated by semicolons. v and p must come first, in that order; the rest may appear in any order.
The ones that matter
- v=DMARC1 is the version. Required, always first, always exactly this.
- p= sets the policy for the domain: none, quarantine or reject. Required.
- rua= is where aggregate reports are sent. A mailto: URI. Technically optional; treat it as required.
- sp= sets the policy for subdomains. Defaults to the value of p, which is usually what you want.
Alignment and sampling
- adkim= sets the DKIM alignment mode: r (relaxed, default) or s (strict).
- aspf= sets the SPF alignment mode: r (relaxed, default) or s (strict).
- pct= applies the policy to this percentage of failing mail. Used for phased rollout under RFC 7489; the DMARCbis revision drops it, and support has always been uneven.
Reporting detail
- ruf= is where failure (forensic) reports are sent. Rarely honoured, and they contain message content.
- fo= selects which failures generate a forensic report: 0 (all fail), 1 (any mechanism fails), d (DKIM fails), s (SPF fails).
- rf= is the failure report format. Effectively always afrf.
- ri= is the aggregate report interval in seconds. Defaults to 86400; receivers are free to ignore anything else.
A fully specified record
v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;
rua=mailto:dmarc@example.com; ri=86400Sending reports to an address at another domain requires that domain to authorise it with a record at example.com._report._dmarc.<their-domain> containing v=DMARC1. Without it, conforming receivers will not send the reports at all.
More on DMARC
What DMARC actually does
DMARC binds SPF and DKIM to the From address your recipients see, tells receivers what to do on failure, and sends you reports about it.
Publishing your first DMARC record
Start at p=none with a reporting address. It changes nothing about delivery and gives you the data you need for every decision that follows.
Alignment, the idea that makes DMARC work
Alignment requires the domain SPF or DKIM authenticated to be the domain your recipient sees. Without it, authentication proves nothing useful.