All tips
DMARC 2 min read

Every DMARC tag, and which ones matter

A DMARC record has eleven possible tags. Four of them do the work; the rest are tuning you will rarely touch.

The record lives at _dmarc.<domain> as a TXT record, with tags separated by semicolons. v and p must come first, in that order; the rest may appear in any order.

The ones that matter

  • v=DMARC1 is the version. Required, always first, always exactly this.
  • p= sets the policy for the domain: none, quarantine or reject. Required.
  • rua= is where aggregate reports are sent. A mailto: URI. Technically optional; treat it as required.
  • sp= sets the policy for subdomains. Defaults to the value of p, which is usually what you want.

Alignment and sampling

  • adkim= sets the DKIM alignment mode: r (relaxed, default) or s (strict).
  • aspf= sets the SPF alignment mode: r (relaxed, default) or s (strict).
  • pct= applies the policy to this percentage of failing mail. Used for phased rollout under RFC 7489; the DMARCbis revision drops it, and support has always been uneven.

Reporting detail

  • ruf= is where failure (forensic) reports are sent. Rarely honoured, and they contain message content.
  • fo= selects which failures generate a forensic report: 0 (all fail), 1 (any mechanism fails), d (DKIM fails), s (SPF fails).
  • rf= is the failure report format. Effectively always afrf.
  • ri= is the aggregate report interval in seconds. Defaults to 86400; receivers are free to ignore anything else.

A fully specified record

v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;
rua=mailto:dmarc@example.com; ri=86400

Sending reports to an address at another domain requires that domain to authorise it with a record at example.com._report._dmarc.<their-domain> containing v=DMARC1. Without it, conforming receivers will not send the reports at all.

Check your DMARC policy
dmarcsyntaxdns