ActiScan
← Email Authentication Fundamentals

Module 4 of 6

DMARC — Policy, Alignment, and Enforcement

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the piece that finally closes the gap both SPF and DKIM leave open on their own: it requires that a passing SPF or DKIM result actually aligns with the visible header From: domain – the one a person reads.

Alignment: relaxed vs. strict

  • Relaxed alignment (the default): the authenticated domain and the header From: domain just need to share the same organizational domain – mail.example.com aligns with example.com.
  • Strict alignment: they must match exactly, subdomain and all.

A message needs SPF or DKIM to both pass and align with the header From: domain to pass DMARC overall.

A real record

v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com
  • p= – the policy: none (monitor only), quarantine (send failing mail to spam), or reject (block it outright).
  • pct= – what percentage of failing mail the policy applies to (useful for a gradual rollout).
  • rua= – where aggregate reports get sent (Module 5 covers what's actually in them).

Why p=none is not protection

This is the single most common DMARC misconception: publishing a DMARC record with p=none does not stop a single spoofed message. It only turns on reporting – you start seeing what's failing and from where, but nothing gets blocked or quarantined until the policy actually moves to quarantine or reject. A domain sitting at p=none indefinitely has all the visibility of DMARC and none of the protection – which is exactly why "monitor, then tighten" has to be a deliberate rollout plan, not a permanent resting state. Course 2 covers building that rollout safely.

Check your own domain's current policy with ActiScan's DMARC checker – and if it's sitting at p=none, that's worth a real plan, not just a passing grade.

Try it yourself: DMARC Record Checker