All tips
DMARC 2 min read

Publishing your first DMARC record

Start at p=none with a reporting address. It changes nothing about delivery and gives you the data you need for every decision that follows.

The first DMARC record you publish should not affect a single message. Its job is to turn on reporting so that, three weeks from now, you know exactly who sends mail as your domain.

Publish this

_dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

Before you publish

  1. Make sure SPF exists and is under the lookup limit.
  2. Make sure DKIM signing is enabled at your primary mail platform.
  3. Create the mailbox for rua and be ready for volume. A mid-sized domain receives dozens of XML attachments a day.

What arrives

Aggregate reports are gzipped XML, one per receiver per day, listing source IPs with message counts and SPF/DKIM results. They are not designed to be read by hand. Drop one into the DMARC report reader to see it in plain English, or feed them to a processor if the volume warrants it.

What to look for in the first month

  • Sources you recognise that are failing. These are configuration gaps to fix.
  • Sources you do not recognise. Resolve the IPs before concluding anything. Most turn out to be forwarders or a forgotten vendor.
  • The proportion of total volume passing. Enforcement is safe when that number is high and the remainder is explained.

Publish a DMARC record on domains that send no mail at all, too. v=DMARC1; p=reject; rua=mailto:dmarc@example.com on a parked domain costs nothing and stops it being used to spoof you.

Check your DMARC policy
dmarcsetuprollout