How to set up DMARC without breaking your email

DMARC stops criminals sending email that looks like it came from your domain. Rolled out in stages, it won't block your real email along the way.

Updated October 4, 2026

Before you start

DMARC builds on SPF and DKIM. A message passes DMARC when it passes SPF or DKIM and the domain that passed matches the domain in the From address. So the first job is making sure every service that sends as your domain, such as Microsoft 365, Google Workspace, your CRM, invoicing tool or newsletter platform, is covered by SPF and, ideally, signs with DKIM.

Steps

  1. 1

    List everything that sends as your domain

    Check your mail platform, marketing and CRM tools, invoicing, helpdesk and website forms. Each one needs to be in SPF or sign with DKIM for your domain.

  2. 2

    Fix SPF

    Publish a single SPF record that includes each sender, for example include:spf.protection.outlook.com for Microsoft 365 or include:_spf.google.com for Google Workspace. Keep it under 10 DNS lookups.

  3. 3

    Turn on DKIM

    Enable DKIM signing in Microsoft 365 or Google Workspace, and in any other service that offers it.

  4. 4

    Publish DMARC at p=none

    Add a TXT record at _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:your-reports-address. This changes nothing about delivery; it starts reports flowing.

  5. 5

    Read the reports for two to four weeks

    Aggregate reports show which servers send as your domain and whether they pass. Fix any legitimate sender that fails.

  6. 6

    Move to quarantine

    Change to p=quarantine, optionally starting with pct=25 and raising it. Failing mail goes to spam rather than the inbox.

  7. 7

    Move to reject

    Once reports are clean, set p=reject. Spoofed mail is now refused outright.

Example records

_dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
_dmarc.example.com  TXT  "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@example.com"
_dmarc.example.com  TXT  "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"

Doing it with TenantWard

The free check shows your current SPF, DKIM and DMARC. Connect Cloudflare, GoDaddy or Route 53 and TenantWard publishes each DMARC stage for you, saving the previous record first so you can undo with one click, and reminds you when it's time to move to the next stage.

Questions

What DMARC policy should I start with?
Start with p=none so you can see who sends as your domain without affecting delivery. Move to quarantine, then reject, once your legitimate senders pass.
Can I have more than one DMARC record?
No. A domain must have exactly one DMARC record at _dmarc. Two records make DMARC invalid, and receivers treat it as if you had none.
Do subdomains need their own DMARC record?
Subdomains inherit the parent's policy unless you set sp= in the parent record or publish a record for the subdomain.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.