SiteAlertAI SiteAlertAI
🛰 Web Scan 🔒 SSL/TLS 📬 MX Record ✉ Email Header 🎣 URL Check 🌍 IP Geo
🛰 Web Scan 🔒 SSL/TLS 📬 MX Record ✉ Email Header 🎣 URL Check 🌍 IP Geo
← All articles
Email Security 2026-02-02 · 6 min read

DMARC: The Policy That Ties SPF and DKIM Together

DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on SPF and DKIM. It tells receiving servers what to do when a message fails authentication, and it sends you reports about who is sending mail using your domain.

The policy levels

  • p=none — monitor only; collect reports without affecting delivery. Start here.
  • p=quarantine — send failing mail to spam.
  • p=reject — refuse failing mail outright. The end goal for full protection.

A safe rollout

Begin with v=DMARC1; p=none; rua=mailto:[email protected]. Review the aggregate reports for a few weeks to confirm your legitimate senders pass, then move to quarantine, and finally reject. Rushing straight to reject can silently drop real mail from a forgotten sender.

Without DMARC at enforcement, anyone can send email that appears to come from your domain. Generate a record and check enforcement in the MX analyser.

Put this into practice
Run a free, private scan — no login, nothing stored.
🛡 Web Scan 🔒 SSL/TLS 📬 MX & Email 🎣 URL Check

Related articles

Email Security SPF Records Explained: Stop Others Spoofing Your Email SPF tells the world which servers may send mail for your domain. Here is how to write one that actually protects you. Email Security DKIM: How a Cryptographic Signature Proves Your Email Is Real DKIM adds a tamper-proof signature to your mail. Here is what it is and how to set it up correctly. Email Security How Email Spoofing Works — and How to Read a Header The "From" address is trivially faked. Learn how spoofing works and how the headers reveal a message's true origin.
SiteAlertAI · © 2026 All rights reserved · Built for security professionals and developers.
Blog Guides Privacy Terms About Contact Social

⚠ For authorised security testing only. Scanning domains you do not own may violate laws in your jurisdiction. SiteAlertAI accepts no liability for misuse. CVE data is indicative — verify with NVD.