Skip to content

What is DMARC? p=none vs quarantine vs reject

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record in which a domain owner tells receiving servers what to do — deliver, quarantine or reject — with mail that fails SPF and DKIM or is not aligned with the visible sender address, and asks for the results to be reported back. It is defined in RFC 7489 and published as a TXT record named _dmarc.<domain>.

This article explains the problem DMARC solves, how the three policies differ and how to move a domain safely to p=reject.

What problem does DMARC solve?

Every email has two sender addresses: the From header that the recipient sees, and the envelope sender (Return-Path) that servers use during delivery. SPF (RFC 7208) checks only the envelope sender's domain; DKIM (RFC 6376) verifies the domain that signed the message (d=). Neither looks at the From address the user sees.

Attackers exploit that gap: they send a message that passes SPF for their own domain but put accounting@ornek.com.tr in the From header. DMARC asks the missing question: is the domain that passed SPF or DKIM the same as the domain in the From header? This is called alignment. To pass DMARC, at least one of SPF or DKIM must both pass and be aligned.

Alignment has two modes:

  • relaxed (default, aspf=r / adkim=r): subdomains match; newsletter.ornek.com.tr is aligned with ornek.com.tr.
  • strict (aspf=s / adkim=s): the domains must be identical.

What does a DMARC record look like?

The minimal form:

_dmarc.ornek.com.tr.  IN  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@ornek.com.tr"

Common tags:

TagMeaning
v=DMARC1Version; must be the first tag.
p=Policy for the domain: none, quarantine or reject.
sp=Separate policy for subdomains; defaults to p=.
rua=Address for aggregate reports.
pct=Percentage of mail the policy applies to; default 100.
adkim= / aspf=DKIM and SPF alignment mode (r or s).

There must not be a second record starting with v=DMARC1 at the same name; receivers ignore DMARC entirely on a domain with two records.

What is the difference between p=none, p=quarantine and p=reject?

p=none only observes. Mail that fails DMARC is still delivered; what you gain is the reports sent to rua. It is the right first step for a new domain, but as a permanent state it offers no protection: spoofed mail keeps reaching inboxes.

p=quarantine asks the receiver to treat failing mail as suspicious, which in practice usually means the junk folder. Spoofed mail is delivered but does not land in front of the user.

p=reject asks the receiver to refuse the message during delivery. Spoofed mail is never delivered. This is the target state.

The pct= tag applies the policy to only a percentage of mail. It can be used to ramp up during a transition, but a record left at pct=25 means the policy is not applied to the rest of the spoofed mail at all.

Why do DMARC reports (rua) matter?

Receiving servers send daily XML reports to the rua address. They list every IP address sending mail as your domain, the volume, and the SPF/DKIM/DMARC result. Without these reports, tightening the policy is guesswork: a forgotten CRM, newsletter service or scan-to-mail printer silently stops working after p=reject.

If the report address is on another domain (for example a report-processing service), that domain must publish a record stating that it accepts the reports:

ornek.com.tr._report._dmarc.report-service.example.  IN  TXT  "v=DMARC1"

How do you move safely to p=reject?

  1. Complete SPF and DKIM. Every service that sends mail must either be listed in SPF or sign with DKIM using your own domain. See How to write an SPF record and What is DKIM?.
  2. Start with p=none and rua. Read the reports for at least a few weeks. If you see a legitimate sender you did not know about, add it to SPF or DKIM.
  3. Apply p=quarantine. Raise the policy once no legitimate sending failures remain in the reports.
  4. Apply p=reject. After a few clean weeks, take the final step.
  5. Do not forget non-sending domains. They can go straight to p=reject:
ornek.com.tr.         IN  TXT  "v=spf1 -all"
_dmarc.ornek.com.tr.  IN  TXT  "v=DMARC1; p=reject;"

Google and Yahoo expect a DMARC record from domains that send in bulk. The record is no longer only a security measure; it has become a deliverability requirement.

What should you do about subdomains?

A DMARC record is published only on the organisational domain (_dmarc.ornek.com.tr) and also applies to subdomains: for invoice.ornek.com.tr, which has no DMARC record of its own, the receiver looks at the parent domain's record. The sp= tag applies a different policy to subdomains.

Attackers often use subdomains that do not exist (e.g. security.ornek.com.tr). Even with p=reject on the domain, a record with sp=none leaves that door open. If you do not send mail from subdomains, leave sp= out or use sp=reject. If you send a newsletter from a subdomain, publish a separate DMARC record for that subdomain and run its own transition.

What does Denetta check in DMARC?

Denetta's Domain and Email Security module audits a domain from the outside, using public information only, with 31 rules. On the DMARC side, the relevant rule codes are:

  • MAIL-006: no DMARC record.
  • MAIL-007: the policy only monitors (p=none).
  • MAIL-008: the policy applies to only part of the mail (pct below 100).
  • MAIL-009: no report address (rua).

An SPF record ending in ~all while DMARC is not enforcing is assessed separately (MAIL-004): ~all only has an effect when DMARC is at quarantine or reject.

Each finding comes with remediation text written for the domain's DNS hosting provider. The text is only displayed; Denetta never changes a DNS record. You make the decision and the change.

To see where your own domain stands, use the domain security check. It reads only DNS records, without connecting to any of your servers, and produces a pre-check score from 21 rules. For the full module, see Domain and Email Security.

Frequently asked questions

Are SPF and DKIM enough without a DMARC record?

No. SPF and DKIM only produce an authentication result; DMARC decides what the receiver does when that result is negative and whether you get reports. SPF also never checks the visible From address; DMARC alignment creates that link.

How long should it take to move from p=none to p=reject?

There is no fixed period. Stay at p=none until every legitimate sender in the aggregate reports passes SPF or DKIM with alignment; then move to p=quarantine, and after a few clean weeks to p=reject.

Does a domain that sends no mail need DMARC?

Yes. Non-sending domains are a common target for spoofing. Publishing v=spf1 -all as SPF and v=DMARC1; p=reject; as DMARC shuts that down.

Can the rua address be on another domain?

Yes, but that domain must publish a DNS record stating that it accepts the reports (RFC 7489, section 7.1). If you use a report-processing service, it usually publishes this record.

How is your domain doing?

Measure your SPF, DKIM, DMARC and DNSSEC records with DNS queries only, without connecting to your servers.

Check your domain

Let’s review your infrastructure together.

Let us show Denetta in a meeting with your own scenario, or request your free first report from a FortiGate backup.