DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on SPF and DKIM. It tells receiving servers what to do when a message fails authentication, and it sends you reports about who is sending mail using your domain.
The policy levels
p=none— monitor only; collect reports without affecting delivery. Start here.p=quarantine— send failing mail to spam.p=reject— refuse failing mail outright. The end goal for full protection.
A safe rollout
Begin with v=DMARC1; p=none; rua=mailto:[email protected]. Review the aggregate reports for a few weeks to confirm your legitimate senders pass, then move to quarantine, and finally reject. Rushing straight to reject can silently drop real mail from a forgotten sender.
Without DMARC at enforcement, anyone can send email that appears to come from your domain. Generate a record and check enforcement in the MX analyser.